Skip to content
This repository was archived by the owner on Sep 8, 2026. It is now read-only.

Update advanced-hunting-emailattachmentinfo-table.md - #307

Merged
Regan Downer (v-regandowner) merged 3 commits into
MicrosoftDocs:publicfrom
PaleSkinnySwede:patch-2
Jul 3, 2026
Merged

Update advanced-hunting-emailattachmentinfo-table.md#307
Regan Downer (v-regandowner) merged 3 commits into
MicrosoftDocs:publicfrom
PaleSkinnySwede:patch-2

Conversation

@PaleSkinnySwede

Copy link
Copy Markdown
Contributor

Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. .exe) while the field is actually a file content type (e.g. txt;text or email;mime or png).

Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. `.exe`) while the field is actually a file content type (e.g. `txt;text` or `email;mime` or `png`).
@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit b99185c:

✅ Validation status: passed

File Status Preview URL Details
defender-xdr/advanced-hunting-emailattachmentinfo-table.md ✅Succeeded

For more details, please refer to the build report.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit 71b119d:

✅ Validation status: passed

File Status Preview URL Details
defender-xdr/advanced-hunting-emailattachmentinfo-table.md ✅Succeeded

For more details, please refer to the build report.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit 808a21e:

✅ Validation status: passed

File Status Preview URL Details
defender-xdr/advanced-hunting-emailattachmentinfo-table.md ✅Succeeded

For more details, please refer to the build report.

@prmerger-automator

Copy link
Copy Markdown
Contributor

David (@PaleSkinnySwede) : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@ShannonLeavitt

Copy link
Copy Markdown
Contributor

Paul Oliveria (@poliveria)

Could you review the proposed changes?

IMPORTANT: When the changes are ready for publication, adding an approval and a #sign-off comment is the best way to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

@prmerger-automator prmerger-automator Bot added the aq-pr-triaged Tracking label for the vendor PR Review team label Jul 2, 2026
@prmerger-automator

Copy link
Copy Markdown
Contributor

David (@PaleSkinnySwede) : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@poliveria

Copy link
Copy Markdown
Collaborator

#sign-off

@prmerger-automator

Copy link
Copy Markdown
Contributor

David (@PaleSkinnySwede) : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@v-regandowner
Regan Downer (v-regandowner) merged commit 6754078 into MicrosoftDocs:public Jul 3, 2026
2 of 4 checks passed
learn-build-service-prod Bot added a commit that referenced this pull request Aug 6, 2026
* Docs: soft rebrand Defender XDR → Defender (batch 612-6) (#8027)

* Docs: soft rebrand Defender XDR → Defender (batch 612-6)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 20 files. Protected references (metadata, includes, UI navigation, image alt text, detection source names, acronym definitions, XDR detection engine names) are preserved.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back Changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix conflict.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/defender-docs (branch public) (#7591)

* Add custom graph cost management link in graph charges section

* Update mdb-faq.yml

Updating public documentation because numerous support cases have been opened due to documentation being unclear. Government customers are not included in this section and should be clarified for customers when trying to understand what licensing is required.

* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#525)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Ofer Schreiber <ofer@bigpanda.io>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update advanced-hunting-emailattachmentinfo-table.md (#307)

Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. `.exe`) while the field is actually a file content type (e.g. `txt;text` or `email;mime` or `png`).

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update advanced-hunting-take-action.md with query reference (#406)

* Update advanced-hunting-take-action.md with query reference

Added Kusto query reference for enabling 'Submit to Microsoft' and 'Initiate automated investigation'. To make it more clear after it was raised in the community

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Update manage-event-based-updates-microsoft-defender-antivirus.md (#345)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update with the correct GPO setting name (#365)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* MDB: Update references to the onboarding (#377)

* fix: MDB, update onboarding, rename MAM to WIP

Azure Portal has slowly but progressively been moved to Entra admin center: Update the URL and the actual naming in the portal.

MAM isn't mentioned it seems to be replaced by Windows Information Protection in the same screen.

* fix: Further replace MAM occurrences by WIP 

MAM wording has been removed from both the old Azure portal, as well as in Entra admin center.

* fix: MDB, add updated screenshot MDM and WIP user scopes

While the structure is mostly unchanged, add new screenshot that includes current namings and same design of selector / radio buttons.

* MDB: Include updated screenshot

Include updated screenshot and update description of the picture.

* MDB: Delete old screenshot of MEM/MAM user scope settings

New picture was added with new name, this one is now obsolete.

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Change MDEConfig.txt to DefenderDTconfig.txt (#418)

"DefenderDT.exe -makeconfig" crates a file named DefenderDTconfig.txt instead of MDEConfig.txt

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Update configure-network-connections-microsoft-defender-antivirus.md (#448)

Fixing broken link for https://learn.microsoft.com/en-us/windows/privacy/manage-windows-1709-endpoints#windows-update

No longer works because of ham-fisted MS redirects.

* Update advanced-hunting-microsoft-defender.md (#343)

Add to "known Issues":
When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting.

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Fix grammar in Teams block entry instructions (#496)

* Fix grammar in Teams block entry instructions

Blocking a domain does not block the Teams meeting invitation itself. Blocking a domain will remove the user from the Teams meeting chat after the meeting ends. The current documentation (Teams Meetings) may be misleading as to suggest that it affects all meetings.

* Fix grammar in Teams block entry instructions

Corrected grammatical errors in the block entry explanation.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Clarify instructions for running Client Analyzer shipped version  (#498)

* Clarify instructions for running Client Analyzer shipped version in live response

Adjust the format which is clearer for binary version and python version separately.

* Update run-analyzer-linux.md

* Fix formatting and wording in run-analyzer-linux.md

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Update faqs-on-tamper-protection.yml (#532)

Remove bracket so link properly connects to target URL

* Update quarantine-shared-mailbox-messages.md (#528)

* Update quarantine-shared-mailbox-messages.md

Updated wording for clarity and expanded scope to include both shared and user mailboxes.

* Update quarantine management instructions and date

Updated the date for the document and refined the instructions for accessing quarantined messages in shared mailboxes.

* Update shared mailbox quarantine management instructions

Clarified that automapping is no longer required for managing quarantined messages in shared mailboxes. Updated conditions for accessing quarantined messages.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Resolve syncing conflicts from repo_sync_working_branch to public (#529)

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-04) (#8059)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix fictional bookmarks AIRA created

Removed redundant options for enabling UEBA and streamlined the text.

* Remove bookmark to nonexistent content

Removed redundant sentence in the UEBA documentation.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update release-notes-recommendations-alerts.md

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [2/2] (#8088)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix metadata for PIM in MDO configuration document

* Fix metadata for safe attachments configuration doc

* Update ms.custom metadata in documentation

* Fix formatting in submissions admin review document

* Fix formatting for ms.custom in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-06) (#8061)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix bad AIRA edit

Updated section header from 'Next steps' to 'Next step'.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b5) (#8096)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting of ms.custom metadata in document

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8060)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8062)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8072)

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8095)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Clarify that the Risky IP address category is dynamic (#8198)

* Clarify that the Risky IP category is dynamic and can expire

Add a note explaining that the Risky category is assigned automatically
based on threat intelligence and is removed if no further malicious
activity is detected. All other categories are assigned manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: AbbyMSFT <88824859+AbbyMSFT@users.noreply.github.com>

* Apply suggestion from @AbbyMSFT

* Apply suggestion from @AbbyMSFT

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* new onboarding (#7970)

* new onboarding

* updates

* updates

---------

Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-usp-test8a-mberdugo) (#8077)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Remove AIRA-duplicated ai-usage metadata

Removed 'ai-usage' line from the document header.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Update approval functionality (#8303)

* Update approval functionality (#8304)

* docs(sentinel): add parameterized notebook jobs

Adds overview and detailed guidance for parameterized notebook jobs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* WI591424: GA transition for serverless containers docs

* Restore historical preview note and keep separate GA release note

* Move June 25 GA note to top of table and section list

* Document Registry access requirement for full Serverless Containers features

* Update defender-for-cloud/release-notes.md

* Update defender-for-cloud/release-notes.md

* Mark Serverless Containers as supported in Defender portal

* Move serverless containers GA date to July 1

* Place July 1 release note under July table

* Set July 1 ms.date across remaining PR pages

* Version 26.1.1 (#8316)

* Version 26.1.1

* Fixes

* Mapping updates to transition from grouped to individual recommendations (#8151)

* Transition from grouped to individual recommendations

* Update transition article with end-state classification for deprecated assessments

- Add explanation of 3 end-states (dynamic substitute, static substitute, no substitute)
- Add End-state and New assessment ID columns to all reference tables
- Change 'NA (Static)' to 'Unknown' in Category column for static substitutes (EDR, SQL)
- Mark EDR and SQL rows as static substitutes with [TBD] new assessment IDs
- Fix HostMisconfiguration → HostMisconfigurations per category list
- Mark GitHub security posture management row as [TBD] pending DevOps partner input
- Add placeholder section for Microsoft Defender for Identity (pending partner review)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date and clarify static substitute guidance

- Add July 31, 2026 as the grouped recommendation deprecation date
- Clarify that static substitute recommendations use 'Unknown' category
  and users should filter by assessment ID, not category filter

Per meeting with Roy Hirsch (June 21, 2026)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "Add July 31 deprecation date and clarify static substitute guidance"

This reverts commit c4f487921093d967d968310ed5e2773e07cf3291.

* Update grouped-to-individual recommendations article per Roy Hirsch review

- Remove IcM routing column from all tables (internal-only, not customer-facing)
- Fix ARG query field: securityCategories -> recommendationCategory
- Fix category name: 'Vulnerabilities' -> 'SoftwareUpdate' recommendation category
- Replace 'assessment key/ID' with 'recommendation ID' throughout
- Replace 'grouped assessment' with 'grouped recommendation' throughout
- Remove 'No substitute' end-state (deprecated items not included in this guide)
- Split each product table into Dynamic substitutes and Static substitutes sections
- Simplify table columns: Dynamic (Recommendation | Recommendation ID | Category),
  Static (Recommendation | Recommendation ID | New recommendation ID)
- Remove IcM routing reference from intro tip and reference section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename 'Recommendation category reference' to 'Recommendation transition reference'

Section now covers both dynamic (category-based) and static (recommendation ID-based)
transitions, so 'category reference' was no longer accurate.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date to transition guides

- Add July 31, 2026 deprecation date in transition-grouped-individual-recommendations.md
  (overview callout, adopting section, what you should do now callout)
- Add July 31, 2026 deprecation date in transition-disable-rules-exemptions.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update transition guide with Roy's final feedback

- SQL databases/servers recs: mark as deprecated, replace static substitute table with note and link to full SQL recommendations reference
- Containers: add Azure (c609cf0f) and AWS (682b2595) running container images as dynamic substitutes mapped to SoftwareUpdate
- GitHub security posture mgmt (fd104c01): update [TBD] with link to full DevOps recommendations reference
- Linux secure boot rec (ad50b498): not added (status unknown per Roy)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix SQL recommendations link to point to VA rules mapping article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Replace internal substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply manual edits and re-apply terminology changes

- Remove Secure Score row from comparison table
- Update vulnerability management example description
- Rename old query label and add note before new query
- Remove Secure Score during transition section
- Change EDR recs to deprecated recommendations
- Replace Dynamic/Static substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix terminology: replace 'Dynamic substitutes' with 'Replaced by individual recommendations' in Containers and DevOps sections; fix garbled text and table in Servers deprecated section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix files moved in error (#8310)

* fix files moved in error

* fixes

* [AIRA] Bot Remediation - AbbyMSFT (defender-docs-pr, 20260615-dfi-root-b-r1) (#8073)

* fix(COPY-EDIT): batch

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b3) (#8094)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix ms.custom field formatting in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8074)

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Restructure MDA TOC around customer journey (#7505)

* Restructure MDA TOC around customer journey

Reorganize from feature-based sections to a lifecycle flow:
Deploy > Connect and discover > Assess risk > Control and protect >
Detect threats > Investigate and respond > Stream to SIEM > Manage

Key changes:
- Dissolve app governance silo into relevant phases
- Merge 'View and manage applications' into discovery
- Merge 'Information protection' into 'Control access and protect data'
- Move AI agent protection into discovery section
- Rename SIEM section to clarify outbound direction
- Move operations guide into 'Manage and configure'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename section to 'Investigate and respond to threats'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add PR target instruction to copilot-instructions.md

Ensure PRs are always created against MicrosoftDocs/defender-docs-pr
rather than the fork.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move app governance setup articles to appropriate sections

- 'Turn on app governance' moves into Configuration (it's a config task)
- 'Get started with app governance' moves into 'Discover and manage
  OAuth apps' (it's a product walkthrough, not deployment)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply content audit: move articles to correct lifecycle phases

Based on full-content audit of 35 cross-cutting articles:

Moved to 'Control access and protect data':
- manage-app-permissions.md (renamed to 'Manage OAuth app permissions')
- app-governance-visibility-insights-sensitive-content.md
- governance-discovery.md
- mde-govern.md
- ai-agent-protection.md and real-time-agent-protection (AI agent protection)

Moved to 'Investigate and respond to threats':
- app-governance-anomaly-detection-alerts.md
- app-governance-investigate-predefined-policies.md
- tutorial-flow.md (response automation, not SIEM)

Kept ai-agent-inventory.md in discovery (primary entry point).
AI agent discovery stays in Connect and discover; protection moves
to Control access.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename discovery sections for clarity

- 'Discover cloud apps (shadow IT)' -> 'Discover cloud apps and shadow IT'
- 'Discover and manage OAuth apps' -> 'Discover and manage OAuth apps with app governance'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Restructure MDA TOC: split discover/connect, rename access section

- Split 'Connect and discover apps' into separate 'Discover apps' and
  'Connect apps' sections, with discovery first
- Rename 'Control access and protect data' to 'Manage access and app behavior'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Consolidate app governance articles and clarify OAuth app scope in titles

- Flatten Connect apps TOC node (remove unnecessary intermediate level)
- Consolidate app governance articles:
  - Merge policies overview + get-started + predefined into single overview
  - Merge policies create + manage into single create-and-manage article
  - Merge threat detection overview + get-started + monitor into single article
  - Merge visibility insights overview + get-started into single article
- Update all app governance TOC nodes and article titles to include 'OAuth'
  to distinguish from SaaS app content
- Add redirects for 6 deleted articles
- Fix all internal links to deleted articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken links in index.yml to deleted articles

Update references to consolidated app governance articles that were
deleted upstream.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Resolve PR review blocking issues: typos, casing, and alt-text fixes

- Fix 'polcies' typo in alt-text (app-policies-overview)
- Add graphic-type prefix to two image alt-texts (app-policies-overview)
- Lowercase 'app governance' in alt-text (detect-remediate-overview)
- Remove duplicate 'the' (secure-apps-access-non-graph-api)
- Lowercase three 'app governance' instances (anomaly-detection-alerts)
- Title case 'Zero Trust' (index.yml)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8075)

Remediation for COPY-EDIT.
Files affected: 6

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-usp-test8a-guywi) (#8076)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title and content in mto-requirements.md

Renamed 'Next steps' section to 'Related content' and updated its content.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8078)

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-b) (#8081)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Improve formatting of simulation automation steps

Formatted the configuration steps into a bulleted list for better readability.

* Update attack-simulation-training-training-campaigns.md

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Update ms.custom metadata in connectors-remove-blocked.md

* Refactor ms.custom metadata in documentation

Updated ms.custom metadata to include a list format.

* Update ms.custom formatting in documentation

* Update ms.custom format in preset-security-policies.md

* Update quarantine-admin-manage-messages-files.md

* Fix formatting of ms.custom property in markdown

* Update ms.custom metadata format in markdown file

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* WI590578-table-insights (#8265)

* WI590578-table-insights

* quality fixes

* additional work

* updated conceptual page

* page quality fixes

* Refine Table insights guidance and restore Data Lake terminology

* Update manage-table-tiers-retention.md

* fixes to instructions

* Update manage-table-tiers-retention.md

* quality fixes

* fix

* fix title

* small fixes

* small fixes

* fix based on Nikita's comment

actually I realized there is one more change when in Whats new section when you click on tables, you can see data sources in side drawer.

* fixing broken list

---------

Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-d) (#8083)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting for ms.custom in alert policies document

* Fix formatting for ms.custom in audit log document

* Fix formatting of ms.custom in documentation

* Fix formatting in connection filter policies document

* Fix formatting in connectors-detect-respond-to-compromise.md

* Remove section for new Microsoft 365 administrators

Removed unnecessary section for new Microsoft 365 administrators and related content. There were no links or anything of value. It was essentially an ad, and even that ad didn't link to anything.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Document AI agent awareness for Entra ID service principals

- Add Used by AI agents (Preview) column to NHI details table
- Add Used by AI agents (Preview) stat to NHI insight cards
- Add what's-new entry for AI agent visibility

Work item: 591169

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Chrisda to Main (#8323)

* Update attack-surface-reduction-rules-reference.md

Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'

* Update attack-surface-reduction-rules-overview.md

Consistency updates

* ASR rules report screenshot updates

More data

* Remove A3 from E3 gets MDO P1 refs

Per request

* Added Teams to report suspicious

* Update outbound-spam-high-risk-delivery-pool-about.md

Content VSO 591495

* [AIRA] Bot Remediation - dansimp (defender-docs-pr, d365-test8b-dansimp) (#8085)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update email-analysis-investigations.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - deniseb (defender-docs-pr, d365-test8b-deniseb) (#8086)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update authorship information in documentation

* Change section title to 'Related content'

Updated section title and added related content links.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Denise Vangel-MSFT <deniseb@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [1/2] (#8087)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Fix formatting in air-report-false-positives-negatives.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-e) [2/2] (#8090)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - unowned (defender-docs-pr, em-test8d) (#8091)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* fix(COPY-EDIT): editorial (#8089)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* CFA article updates (#8149)

* Configure controlled folder access

* Added Windows Security app procedures

And removed them elsewhere

* CFA overview article rename

* CFA

* CFA Overview

* Delete customize-controlled-folders.md

* Removed CFA article from MDB

And also cleaned up ASR/ASR rule references and links, including any Intune procedure links.

* Link and link title updates for CFA

* Update address-unwanted-behaviors-mde.md

* New monitor CFA article

Remnants of the old evaluate CFA article + Windows event viewer steps/info from the CFA overview article.

* Copy and Technical edits

* CFA demonstrations

* CFA demos

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* CFA/ASR demo updates

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* Final edits

* Offending file name renames

Per build report

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-c) (#8082)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update address-compromised-users-quickly.md

* Fix formatting of ms.custom metadata in markdown

* Fix formatting of custom metadata in markdown file

* Correct 'ms.custom' formatting in documentation

Fixed formatting of the 'ms.custom' metadata entry.

* Update custom metadata in mdo-portal-permissions.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8053)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* docs(sentinel): add parameterized notebook job guidance

Add steps for defining notebook parameters, refreshing job parameters, and overriding values when running a notebook job manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 11) - NEW SERIES, IGNORE BATCH NUMBER (#7939)

* Docs: soft rebrand Defender XDR to Defender (batch 11)

Replace 'Defender XDR' and 'Microsoft Defender XDR' with 'Defender' and
'Microsoft Defender' in body text of 20 advanced hunting schema and
feature articles, per Microsoft Defender branding guidelines.

Preserved unchanged:
- appliesto metadata fields
- [!INCLUDE references
- ms.service and other metadata fields
- Link display text referencing external page titles
- URL paths and fragments

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back change.

Updated description to specify Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-2) (#8016)

* Docs: soft rebrand Defender XDR → Defender (batch 612-2)

Update 18 advanced hunting files to replace 'Defender XDR' and
'Microsoft Defender XDR' with 'Defender' and 'Microsoft Defender'
in body text per branding guidelines. Protected references
(metadata, includes, API names, historical records, plugin names)
are left unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

* Roll back change.

* Roll back change.

Updated the description to include 'XDR' in the title.

* Roll back change.

* Roll back changes.

Updated references to Microsoft Defender XDR in the document.

* Roll back changes.

Updated references from Microsoft Defender for Endpoint to Microsoft Defender XDR in the migration guide.

* Roll back changes.

* Roll back changes.

Updated title and references to reflect Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-9) (#8030)

* Docs: soft rebrand Defender XDR → Defender (batch 612-9)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 10 files. 1 file had no eligible changes (all XDR refs were protected product names).

Protected references preserved: metadata fields, [!INCLUDE] lines, image alt text, historical changelog entries in whats-new.md, API endpoint names, external blog post titles, 'Defender Experts for XDR' product name, XDR capability descriptions (XDR solution, XDR tools, XDR/SIEM).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR, including changes to titles and descriptions throughout the content.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix typo in Microsoft Defender XDR description

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Fix directory path and update checksum commands (#8334)

Command errors caused by folder structure or incorrect quotation/space within a zip file.

* Clarify prerequisites for attack disruption exclusions based on Unified RBAC state (#8276)

Split the Prerequisites section into Device and Identity exclusion
permissions, showing the required roles when Unified RBAC is enabled
versus disabled. Cross-link to Unified RBAC activation and custom
permissions docs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#8341)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update value-data-connectors.md with onboarding notes (#8254)

* Update value-data-connectors.md with onboarding notes

Added note about device onboarding requirements and limitations.

* Apply suggestion from @DebLanger

* Update date and permissions in get-machines.md (#8344)

Updated the date and permissions section in the API documentation.

* wi-589516: Remove '| Microsoft Docs' suffix from title metadata (#8255)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>

* Update email post delivery events documentation

* Learn Editor: Update fixed-reported-inaccuracies.md (#8308)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA (#8354)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA

* Updating what's new

* Removing preview note

* Docs: soft rebrand Defender XDR → Defender (batch 2) (#8191)

* Docs: soft rebrand Defender XDR → Defender (batch 2)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR'
with 'Defender' in eligible locations per branding guidelines.

Files updated:
- critical-asset-management.md (1 replacement)
- get-started-exposure-management.md (4 replacements)
- prerequisites.md (3 replacements)
- whats-new.md (0 - all references in historical What's New entries)

Preserved XDR references in:
- Bold UI navigation paths (prerequisites.md line 67)
- Historical What's New entries (whats-new.md lines 179, 310)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 13) (#7941)

* docs: soft rebrand Defender XDR → Defender (batch 13)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers (#8350)

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers

- Add limitation note to Security findings (Preview) component in AKS, EKS, and GKE tabs
  stating it cannot be enabled through Azure Policy and must be toggled in plan Settings
- Rename 'Security findings' to 'Security findings (Preview)' for accuracy
- Remove 'This article explains' from opening line per style guide

Addresses US585115 / IcM 662676555 / CxE WI 19929

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestions from code review

Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add identity assessment key mappings to transition reference article (#8351)

* Add identity assessment key mappings to transition reference article

Replace placeholder in Microsoft Defender for Identity section with
assessment key mapping table for 5 guest/disabled account assessments.
Uses 'assessment' terminology per Roy's guidance.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8050)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8048)

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentinel-mberdugo-02) (#8047)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title from 'Next steps' to 'Related content'

* Fix formatting of title in integration guide

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Cloud security reporting GA (#8267)

* Cloud security reporting GA: remove preview, add release note and card customization

- Remove (Preview) from title and H1 in cloud-security-reporting.md
- Remove preview features prerequisite
- Add card customization capability
- Add June 30 GA release note entry

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add customize cards section with screenshots to cloud reporting article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Clarify that card customization is only for cards labeled Customizable

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add migration guidance for Sentinel incident creation rules to Defender alert grouping (#7952)

* Add Sentinel-to-Defender alert grouping migration guidance

* Relocate Sentinel migration article to unified-secops docset

* Update migration images and include restored xdr article copy

* Remove duplicate defender-xdr migration article copy

* Update image alt text for incident correlation migration doc

* Fix validation issues for incident correlation migration docs

* Fix broken migration link and update image references

* israel review

* Fix PR validation issues for links, metadata, and image naming

* Fix broken unified secops migration links

* Remove image from incident creation migration article

* Remove unused onboarding image file

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Revert to correct cross-docset URL link for new migrate-sentinel article

* Revert to correct cross-docset URL link for new migrate-sentinel article

---------

Co-authored-by: Guy Wild <98332688+guywi-ms@users.noreply.github.com>

* Clarify DlpInfo description in deviceinfo table

Updated DlpInfo description to clarify its content and added a reference link for further information.

* GA multicloud recommendations June 30: release notes, score impact, new tag docs, reference updates (#8275)

* Docs: GA multicloud recommendations June 30 - score impact, new tag, ref updates

- Add June 30 GA release note for expanded multicloud coverage
  (~150 recommendations, ~90 resource types, score impact)
- Add GA/Preview rows to recommendations release notes
- Document 'New' tag (30-day window), change log, and portal banner
  in review-security-recommendations.md (both portal pivots)
- Add Secure Score impact callout to secure-score-security-controls.md
- Remove (Preview) from 217 multicloud recommendations across 6
  reference files (networking, data, identity-access, app-services,
  compute, container)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix: restore deleted category tabs and select step in review-security-recommendations.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix DlpInfo reference link in deviceinfo-table.md

Updated the reference link for DlpInfo properties to ensure it points to the correct documentation.

* Add event-driven response guide for Defender for Storage malware scanning (#8345)

- Expand Event Grid setup walkthrough in configure-malware-scan article with 3-step process
- Add 3 Azure Functions templates: quarantine, auto-delete, and alert/notification
- Add sample payloads for No threats found and Not Scanned result types
- Add event delivery troubleshooting section covering permissions, networking, and subscription validation
- Add Event-driven response feature bullet to introduction article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Align identity risk score GA heading with what's-new convention

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Widespread Local Admin predefined classification rules (#8289)

* Add Widespread Local Admin classification rules and release note

- Add three new Identity classification rules to predefined classifications:
  Widespread Local Admin on Servers (High), Widespread Local Admin on
  Workstations (High), and Widespread Local Admin on Servers and
  Workstations (Very High)
- Add June 2026 release note entry for the new Identity classifications

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Reorder Widespread Local Admin rules and add dependency note

- Reorder to: Servers, Workstations, Servers and Workstations in both files
- Add note to 'Servers and Workstations' rule indicating it relies on
  the Servers and Workstations classifications

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* wi-586653-USX-transition-docs-improvements-CxE (#8183)

* wi-586653-USX-transition-docs-improvements-CxE

Changes:
 Investigation row (line 50):

   - Added hyperlinks to "Attack story" and "incident graph" � /defender-xdr/investigate-incidents#attack-story
   - Added blast radius analysis mention with link � /defender-xdr/investigate-incidents#blast-radius-analysis
   - Removed "(Sentinel Graph)" label � the actual feature name is just "incident graph"

  Security Copilot row (line 58):

   - Added "autonomous Security Copilot agents" with link � /defender-xdr/security-copilot-agents-defender
   - Added "threat hunting" agent link � /defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent
   - Added "Included capacity for E5/E7 customers" with link � /copilot/security/security-copilot-inclusion
   - Updated Benefits column: "agentic defense" added

* mto - playbooks and lighthouse

 Changes in sentinel/move-to-defender.md:

   - Added IMPORTANT callout clarifying that MTO doesn't replace Azure Lighthouse (gap 10), listing operations that still require Lighthouse
   - Added note that playbooks can't be distributed through MTO content distribution, with CI/CD workaround (gap 11)

* Update move-to-defender.md

Changes in sentinel/move-to-defender.md:

 - Gap 13 (SCU inclusion): Added E5/E7 included Security Copilot capacity mention with link to the existing NOTE callout about transition costs
 - Gap 15 (Investigation visuals): Added paragraph about attack story, incident graph, and blast radius analysis with links, under "Update incident triage processes"
 - Gap 8 (AAD/UEBA): Added note at end of UEBA section explaining that Sentinel UEBA signals feed into automatic attack disruption after transition, with link
 - Gap 12 (SOC Optimization): Added new "Use SOC optimization recommendations" subsection explaining cross-service vs Sentinel-only differences, with links to docs and API

* fix build error

* added "prioritize containment actions"

* small tweaks

* corrections

* Update move-to-defender.md

* Alert trigger scope limitation updates

1. In create-manage-use-automation-rules.md, after the trigger table, a NOTE now says:

“In the Defender portal, alert triggers work only on Microsoft Sentinel alerts,” and links to Enhanced Alert Trigger (Public Preview).

2. Updated core automation rules limitation text to include the solution path:

In automate-incident-handling-with-automation-rules.md, the NOTE under alert-triggered automation now explicitly says Defender XDR alert-triggered automation isn’t available in the Defender portal and points to Enhanced Alert Trigger (Public Preview).

3. Standardized migration/transition include messaging so the limitation points to the preview workaround:

In automation-in-defender.md, the “Automation rules with alert triggers” row now includes the limitation plus a direct link to Enhanced Alert Trigger (Public Preview).

4. Made the destination feature explicitly labeled as preview:

In generate-playbook.md, the section heading was updated to “Enhanced alert trigger (Public Preview).”

* Bookmark deprecation

* 5–10 minute batching window

updated note in sentinel\automate-incident-handling-with-automation-rules.md

* data lake - regional data processing limitation

* mutli-tenant: Playbooks not distributable via MTM

* Multitenant operations (MTO) and Azure Lighthouse

* PR build errors + bookmarks- advanced hunting

* Adjusting spacing between tables

* Clarify bookmarks note

* Removed "Public" from "Public Preview"

* bookmarks update

* bookmarks tweak

* 5-10 min lag - formatting

* ueba update

* Update advanced-hunting-microsoft-defender.md

* Remove (Preview) from enhanced triggers

Confirmed with PM Guy Shmeltzer, enhanced triggers are already GA

* Move MTO vs Azure Lighthouse content to separate branch/PR (wi-592684)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move WIP content to part-2 branch; revert unresolved items to main

Removes still-in-progress content (AAD context, E5/E7 Copilot capacity, SOC
optimization subsection, regional workspace support, MTM playbook distribution)
from the publishing branch. Adaptations reverted to main; pure additions removed.
Approved content retained.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken link to migrate-sentinel-incident-creation-rules-alert-grouping

Correct the docset path from /unified-secops/ to /unified-secops-platform/ where
the target article actually resides.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken migrate-rules link in Defender-Sentinel integration article

Correct /unified-secops/ to /unified-secops-platform/ for the migrate article path.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* mshta recommendation - GA

* Add AI agent predefined classification rules (#8317)

- Add new AI agent category to predefined classifications
- Add Executive-Sponsored AI Agent rule (Medium criticality)
- Add AI Agent with Privileged Business System Write Access rule (Medium criticality)
- Add what's new entry for June 2026

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Eliminate redundant click-through procedures in Defender for Endpoint content (1 of 2) (#8339)

* Eliminate redundant click-through procedures in Defender for Endpoint content

* Fix bullets

* Add docs

* Add files

* Add files

* Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2) (#8359)

* Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2)

* Fix warning

* Update release-notes.md (#8365)

* Learn Editor: Update release-notes.md

* Learn Editor: Update release-notes.md

* Update support-matrix-defender-for-cloud.md (#8364)

* Learn Editor: Update support-matrix-defender-for-cloud.md

* Learn Editor: Update support-matrix-defender-for-cloud.md

* Update regional-availability.md (#8363)

* Learn Editor: Update regional-availability.md

* Learn Editor: Update regional-availability.md

* Add UAE North and UAE Central support for Defender for APIs and API security posture management in DCSPM (#8325)

* Add UAE North and UAE Central support for Defender for APIs and API security posture

Microsoft Defender for APIs and API security posture management in Defender CSPM now support the UAE North and UAE Central Azure regions. Update region lists and add a release note for the June 29, 2026 release.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 23) (#7959)

* docs: soft rebrand Defender XDR → Defender (batch 23)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 18) (#7954)

* docs: soft rebrand Defender XDR → Defender (batch 18)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 21) (#7957)

* docs: soft rebrand Defender XDR → Defender (batch 21)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Address build warning.

Added a section on required permissions for Defender for Identity in Microsoft Defender.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "[AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentine…" (#8373)

This reverts commit 7138bc781bf3c32c0099bd2c8b5d60ccaa4f1ab9.

* Revert "fix(COPY-EDIT): editorial (#8048)" (#8374)

This reverts commit b7e81b8cbc50a5adb4b767a180ec86ce16857156.

* Revert "fix(COPY-EDIT): editorial (#8050)" (#8375)

This reverts commit d054038bbad2c30c31aa5a112a18cdfffd9f9f1f.

* Add Simple Flows automation rules article (AB#570290) (#7690)

* Update Simple Flows action references table and TOC

* Fix broken bookmark in permissions link

The target article doesn't have a #permissions-for-automation-rules anchor.
Drop the anchor and link to the article generally.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Dissolve Known limitations section into action context

Move each limitation next to the action it constrains:
- Email-wide constraints (fixed template, fixed sender, no CC/BCC, no audit log) consolidated into a single NOTE callout after the Actions reference table.
- Assign SLA Policy: existing-policy caveat appended to the action's Behavior cell.
- 10-tasks-per-rule limit was already documented in the Add Task row, so the duplicate bullet is dropped.

Also align Update Case field labels with the feature spec (Email recipients, Grace period).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Cross-link Simple Flows from existing automation-rules articles

Add NOTE callouts pointing to the new Simple Flows article from:
- automate-incident-handling-with-automation-rules.md (Triggers + Actions sections)
- create-manage-use-automation-rules.md (Choose your trigger + Add actions sections)

Each callout is gated on Defender-portal onboarding to match the new feature's availability.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply review must-fixes: title preview tag, capitalization, link text, missing space

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove em-dashes from prose; convert two cross-link NOTEs to inline

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Expand SOC/SLA/SOAR acronyms; reorder What is before Prerequisites

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add portal navigation to Examples 2-4; clearer phrasing on case-trigger cross-link

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply Guy's feedback: broaden to Defender portal scope; drop Assign SLA Policy; new examples; case custom fields

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Drop SLA examples; keep Update Alert and Add Task examples only

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Simplify rule-layering tip

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove SLA Exceeded Email action and update examples

Removed the 'Send Case SLA Exceeded Email' action from the automation rules table and updated example instructions for creating automation rules.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Guy Wild <98332688+guywi-ms@users.noreply.github.com>
Co-authored-by: Dennis Rea <v-denrea@microsoft.com>

* Chrisda to Main (#8377)

* Update attack-surface-reduction-rules-reference.md

Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'

* Update attack-surface-reduction-rules-overview.md

Consistency updates

* ASR rules report screenshot updates

More data

* Remove A3 from E3 gets MDO P1 refs

Per request

* Added Teams to report suspicious

* Update outbound-spam-high-risk-delivery-pool-about.md

Content VSO 591495

* Update anti-phishing-policies-about.md

Per IM request

* Approval update (#8379)

* URBAC by default updates (#7804)

* URBAC by default updates

* URBAC edits/additions per PM feedback

* Fix renamed Defender portal icon links after merging main

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update configure-unified-rbac-for-mdo.md

Removed Sample deployment models section per PM request prior to publish

* Copy edits

* File rename per build report

* File rename per build report

* File rename per build report

* File rename per build report

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* WI593231 malware detection GA

* Update triage agents to use least-privilege email permission (#8034)

* Update triage agents to use least-privilege email permission

Replace the broad 'Email & collaboration content (read)' permission with
the more limited 'Email & collaboration content: Emails associated with
alerts (read)' permission in the Phishing Triage Agent and Security Alert
Triage Agent docs. This restricts agent access to only emails associated
with alerts, improving security posture.

Also adds a what's-new entry for June 2026.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Replace permission screenshots with updated UI showing least-privilege option

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* WI593234-agentless scanning vm update

* Add get started article for Defender security for AI agents (#8296)

* Add get started article for Defender security for AI agents

Create get-started-defender-security-for-ai.md covering the onboarding
flow: enabling data collection, connecting Microsoft 365 connector,
and onboarding Copilot Studio real-time protection. Add TOC entry.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add screenshots to Defender security for AI get started article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove redundant Power Platform integration URL screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* updates

* Update security-for-ai-setup-checklist.png

* Update get-started-defender-security-for-ai.md

* Update get-started-defender-security-for-ai.md

* Split AI agent detection/protection doc into detect-investigate and real-time protection pages

- Repurpose ai-agent-detection-protection.md to focus on detection and investigation
- Add ai-agent-real-time-protection.md covering RTP, policy rules, and prompt evidence
- Add real-time protection policy experience screenshots
- Update TOC, cross-links, and Next steps in related articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Group AI agent security articles under 'Protect AI agents' subnode

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename real-time protection TOC node to 'Block agent threats in real time'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Order real-time protection before detect and investigate in agent security TOC

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Align agent security articles: standardize AgentsInfo table, RTP policy path, remove Preview labels

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix legacy table name to AIAgentsInfo and remove appliesto block from inventory article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename real-time protection node and move it after Get started in agent security TOC

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove temporary Defender for Cloud Apps onboarding notes from agent security articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rework agent onboarding to drop MDA framing: move prereqs, remove extended-detection section, point Copilot Studio to Get started

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove Agent 365 subscription notes and preview-feature prerequisites from agent articles

Co-authored-by: Copilot…
learn-build-service-prod Bot added a commit that referenced this pull request Aug 7, 2026
…s://github.com/MicrosoftDocs/defender-docs (branch public) (#7591)

* Add custom graph cost management link in graph charges section

* Update mdb-faq.yml

Updating public documentation because numerous support cases have been opened due to documentation being unclear. Government customers are not included in this section and should be clarified for customers when trying to understand what licensing is required.

* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#525)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Ofer Schreiber <ofer@bigpanda.io>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update advanced-hunting-emailattachmentinfo-table.md (#307)

Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. `.exe`) while the field is actually a file content type (e.g. `txt;text` or `email;mime` or `png`).

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update advanced-hunting-take-action.md with query reference (#406)

* Update advanced-hunting-take-action.md with query reference

Added Kusto query reference for enabling 'Submit to Microsoft' and 'Initiate automated investigation'. To make it more clear after it was raised in the community

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Update manage-event-based-updates-microsoft-defender-antivirus.md (#345)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update with the correct GPO setting name (#365)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* MDB: Update references to the onboarding (#377)

* fix: MDB, update onboarding, rename MAM to WIP

Azure Portal has slowly but progressively been moved to Entra admin center: Update the URL and the actual naming in the portal.

MAM isn't mentioned it seems to be replaced by Windows Information Protection in the same screen.

* fix: Further replace MAM occurrences by WIP 

MAM wording has been removed from both the old Azure portal, as well as in Entra admin center.

* fix: MDB, add updated screenshot MDM and WIP user scopes

While the structure is mostly unchanged, add new screenshot that includes current namings and same design of selector / radio buttons.

* MDB: Include updated screenshot

Include updated screenshot and update description of the picture.

* MDB: Delete old screenshot of MEM/MAM user scope settings

New picture was added with new name, this one is now obsolete.

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Change MDEConfig.txt to DefenderDTconfig.txt (#418)

"DefenderDT.exe -makeconfig" crates a file named DefenderDTconfig.txt instead of MDEConfig.txt

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Update configure-network-connections-microsoft-defender-antivirus.md (#448)

Fixing broken link for https://learn.microsoft.com/en-us/windows/privacy/manage-windows-1709-endpoints#windows-update

No longer works because of ham-fisted MS redirects.

* Update advanced-hunting-microsoft-defender.md (#343)

Add to "known Issues":
When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting.

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Fix grammar in Teams block entry instructions (#496)

* Fix grammar in Teams block entry instructions

Blocking a domain does not block the Teams meeting invitation itself. Blocking a domain will remove the user from the Teams meeting chat after the meeting ends. The current documentation (Teams Meetings) may be misleading as to suggest that it affects all meetings.

* Fix grammar in Teams block entry instructions

Corrected grammatical errors in the block entry explanation.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Clarify instructions for running Client Analyzer shipped version  (#498)

* Clarify instructions for running Client Analyzer shipped version in live response

Adjust the format which is clearer for binary version and python version separately.

* Update run-analyzer-linux.md

* Fix formatting and wording in run-analyzer-linux.md

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Update faqs-on-tamper-protection.yml (#532)

Remove bracket so link properly connects to target URL

* Update quarantine-shared-mailbox-messages.md (#528)

* Update quarantine-shared-mailbox-messages.md

Updated wording for clarity and expanded scope to include both shared and user mailboxes.

* Update quarantine management instructions and date

Updated the date for the document and refined the instructions for accessing quarantined messages in shared mailboxes.

* Update shared mailbox quarantine management instructions

Clarified that automapping is no longer required for managing quarantined messages in shared mailboxes. Updated conditions for accessing quarantined messages.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Resolve syncing conflicts from repo_sync_working_branch to public (#529)

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-04) (#8059)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix fictional bookmarks AIRA created

Removed redundant options for enabling UEBA and streamlined the text.

* Remove bookmark to nonexistent content

Removed redundant sentence in the UEBA documentation.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update release-notes-recommendations-alerts.md

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [2/2] (#8088)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix metadata for PIM in MDO configuration document

* Fix metadata for safe attachments configuration doc

* Update ms.custom metadata in documentation

* Fix formatting in submissions admin review document

* Fix formatting for ms.custom in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-06) (#8061)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix bad AIRA edit

Updated section header from 'Next steps' to 'Next step'.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b5) (#8096)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting of ms.custom metadata in document

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8060)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8062)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8072)

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8095)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Clarify that the Risky IP address category is dynamic (#8198)

* Clarify that the Risky IP category is dynamic and can expire

Add a note explaining that the Risky category is assigned automatically
based on threat intelligence and is removed if no further malicious
activity is detected. All other categories are assigned manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: AbbyMSFT <88824859+AbbyMSFT@users.noreply.github.com>

* Apply suggestion from @AbbyMSFT

* Apply suggestion from @AbbyMSFT

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* new onboarding (#7970)

* new onboarding

* updates

* updates

---------

Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-usp-test8a-mberdugo) (#8077)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Remove AIRA-duplicated ai-usage metadata

Removed 'ai-usage' line from the document header.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Update approval functionality (#8303)

* Update approval functionality (#8304)

* docs(sentinel): add parameterized notebook jobs

Adds overview and detailed guidance for parameterized notebook jobs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* WI591424: GA transition for serverless containers docs

* Restore historical preview note and keep separate GA release note

* Move June 25 GA note to top of table and section list

* Document Registry access requirement for full Serverless Containers features

* Update defender-for-cloud/release-notes.md

* Update defender-for-cloud/release-notes.md

* Mark Serverless Containers as supported in Defender portal

* Move serverless containers GA date to July 1

* Place July 1 release note under July table

* Set July 1 ms.date across remaining PR pages

* Version 26.1.1 (#8316)

* Version 26.1.1

* Fixes

* Mapping updates to transition from grouped to individual recommendations (#8151)

* Transition from grouped to individual recommendations

* Update transition article with end-state classification for deprecated assessments

- Add explanation of 3 end-states (dynamic substitute, static substitute, no substitute)
- Add End-state and New assessment ID columns to all reference tables
- Change 'NA (Static)' to 'Unknown' in Category column for static substitutes (EDR, SQL)
- Mark EDR and SQL rows as static substitutes with [TBD] new assessment IDs
- Fix HostMisconfiguration → HostMisconfigurations per category list
- Mark GitHub security posture management row as [TBD] pending DevOps partner input
- Add placeholder section for Microsoft Defender for Identity (pending partner review)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date and clarify static substitute guidance

- Add July 31, 2026 as the grouped recommendation deprecation date
- Clarify that static substitute recommendations use 'Unknown' category
  and users should filter by assessment ID, not category filter

Per meeting with Roy Hirsch (June 21, 2026)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "Add July 31 deprecation date and clarify static substitute guidance"

This reverts commit c4f487921093d967d968310ed5e2773e07cf3291.

* Update grouped-to-individual recommendations article per Roy Hirsch review

- Remove IcM routing column from all tables (internal-only, not customer-facing)
- Fix ARG query field: securityCategories -> recommendationCategory
- Fix category name: 'Vulnerabilities' -> 'SoftwareUpdate' recommendation category
- Replace 'assessment key/ID' with 'recommendation ID' throughout
- Replace 'grouped assessment' with 'grouped recommendation' throughout
- Remove 'No substitute' end-state (deprecated items not included in this guide)
- Split each product table into Dynamic substitutes and Static substitutes sections
- Simplify table columns: Dynamic (Recommendation | Recommendation ID | Category),
  Static (Recommendation | Recommendation ID | New recommendation ID)
- Remove IcM routing reference from intro tip and reference section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename 'Recommendation category reference' to 'Recommendation transition reference'

Section now covers both dynamic (category-based) and static (recommendation ID-based)
transitions, so 'category reference' was no longer accurate.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date to transition guides

- Add July 31, 2026 deprecation date in transition-grouped-individual-recommendations.md
  (overview callout, adopting section, what you should do now callout)
- Add July 31, 2026 deprecation date in transition-disable-rules-exemptions.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update transition guide with Roy's final feedback

- SQL databases/servers recs: mark as deprecated, replace static substitute table with note and link to full SQL recommendations reference
- Containers: add Azure (c609cf0f) and AWS (682b2595) running container images as dynamic substitutes mapped to SoftwareUpdate
- GitHub security posture mgmt (fd104c01): update [TBD] with link to full DevOps recommendations reference
- Linux secure boot rec (ad50b498): not added (status unknown per Roy)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix SQL recommendations link to point to VA rules mapping article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Replace internal substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply manual edits and re-apply terminology changes

- Remove Secure Score row from comparison table
- Update vulnerability management example description
- Rename old query label and add note before new query
- Remove Secure Score during transition section
- Change EDR recs to deprecated recommendations
- Replace Dynamic/Static substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix terminology: replace 'Dynamic substitutes' with 'Replaced by individual recommendations' in Containers and DevOps sections; fix garbled text and table in Servers deprecated section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix files moved in error (#8310)

* fix files moved in error

* fixes

* [AIRA] Bot Remediation - AbbyMSFT (defender-docs-pr, 20260615-dfi-root-b-r1) (#8073)

* fix(COPY-EDIT): batch

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b3) (#8094)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix ms.custom field formatting in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8074)

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Restructure MDA TOC around customer journey (#7505)

* Restructure MDA TOC around customer journey

Reorganize from feature-based sections to a lifecycle flow:
Deploy > Connect and discover > Assess risk > Control and protect >
Detect threats > Investigate and respond > Stream to SIEM > Manage

Key changes:
- Dissolve app governance silo into relevant phases
- Merge 'View and manage applications' into discovery
- Merge 'Information protection' into 'Control access and protect data'
- Move AI agent protection into discovery section
- Rename SIEM section to clarify outbound direction
- Move operations guide into 'Manage and configure'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename section to 'Investigate and respond to threats'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add PR target instruction to copilot-instructions.md

Ensure PRs are always created against MicrosoftDocs/defender-docs-pr
rather than the fork.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move app governance setup articles to appropriate sections

- 'Turn on app governance' moves into Configuration (it's a config task)
- 'Get started with app governance' moves into 'Discover and manage
  OAuth apps' (it's a product walkthrough, not deployment)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply content audit: move articles to correct lifecycle phases

Based on full-content audit of 35 cross-cutting articles:

Moved to 'Control access and protect data':
- manage-app-permissions.md (renamed to 'Manage OAuth app permissions')
- app-governance-visibility-insights-sensitive-content.md
- governance-discovery.md
- mde-govern.md
- ai-agent-protection.md and real-time-agent-protection (AI agent protection)

Moved to 'Investigate and respond to threats':
- app-governance-anomaly-detection-alerts.md
- app-governance-investigate-predefined-policies.md
- tutorial-flow.md (response automation, not SIEM)

Kept ai-agent-inventory.md in discovery (primary entry point).
AI agent discovery stays in Connect and discover; protection moves
to Control access.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename discovery sections for clarity

- 'Discover cloud apps (shadow IT)' -> 'Discover cloud apps and shadow IT'
- 'Discover and manage OAuth apps' -> 'Discover and manage OAuth apps with app governance'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Restructure MDA TOC: split discover/connect, rename access section

- Split 'Connect and discover apps' into separate 'Discover apps' and
  'Connect apps' sections, with discovery first
- Rename 'Control access and protect data' to 'Manage access and app behavior'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Consolidate app governance articles and clarify OAuth app scope in titles

- Flatten Connect apps TOC node (remove unnecessary intermediate level)
- Consolidate app governance articles:
  - Merge policies overview + get-started + predefined into single overview
  - Merge policies create + manage into single create-and-manage article
  - Merge threat detection overview + get-started + monitor into single article
  - Merge visibility insights overview + get-started into single article
- Update all app governance TOC nodes and article titles to include 'OAuth'
  to distinguish from SaaS app content
- Add redirects for 6 deleted articles
- Fix all internal links to deleted articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken links in index.yml to deleted articles

Update references to consolidated app governance articles that were
deleted upstream.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Resolve PR review blocking issues: typos, casing, and alt-text fixes

- Fix 'polcies' typo in alt-text (app-policies-overview)
- Add graphic-type prefix to two image alt-texts (app-policies-overview)
- Lowercase 'app governance' in alt-text (detect-remediate-overview)
- Remove duplicate 'the' (secure-apps-access-non-graph-api)
- Lowercase three 'app governance' instances (anomaly-detection-alerts)
- Title case 'Zero Trust' (index.yml)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8075)

Remediation for COPY-EDIT.
Files affected: 6

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-usp-test8a-guywi) (#8076)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title and content in mto-requirements.md

Renamed 'Next steps' section to 'Related content' and updated its content.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8078)

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-b) (#8081)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Improve formatting of simulation automation steps

Formatted the configuration steps into a bulleted list for better readability.

* Update attack-simulation-training-training-campaigns.md

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Update ms.custom metadata in connectors-remove-blocked.md

* Refactor ms.custom metadata in documentation

Updated ms.custom metadata to include a list format.

* Update ms.custom formatting in documentation

* Update ms.custom format in preset-security-policies.md

* Update quarantine-admin-manage-messages-files.md

* Fix formatting of ms.custom property in markdown

* Update ms.custom metadata format in markdown file

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* WI590578-table-insights (#8265)

* WI590578-table-insights

* quality fixes

* additional work

* updated conceptual page

* page quality fixes

* Refine Table insights guidance and restore Data Lake terminology

* Update manage-table-tiers-retention.md

* fixes to instructions

* Update manage-table-tiers-retention.md

* quality fixes

* fix

* fix title

* small fixes

* small fixes

* fix based on Nikita's comment

actually I realized there is one more change when in Whats new section when you click on tables, you can see data sources in side drawer.

* fixing broken list

---------

Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-d) (#8083)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting for ms.custom in alert policies document

* Fix formatting for ms.custom in audit log document

* Fix formatting of ms.custom in documentation

* Fix formatting in connection filter policies document

* Fix formatting in connectors-detect-respond-to-compromise.md

* Remove section for new Microsoft 365 administrators

Removed unnecessary section for new Microsoft 365 administrators and related content. There were no links or anything of value. It was essentially an ad, and even that ad didn't link to anything.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Document AI agent awareness for Entra ID service principals

- Add Used by AI agents (Preview) column to NHI details table
- Add Used by AI agents (Preview) stat to NHI insight cards
- Add what's-new entry for AI agent visibility

Work item: 591169

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Chrisda to Main (#8323)

* Update attack-surface-reduction-rules-reference.md

Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'

* Update attack-surface-reduction-rules-overview.md

Consistency updates

* ASR rules report screenshot updates

More data

* Remove A3 from E3 gets MDO P1 refs

Per request

* Added Teams to report suspicious

* Update outbound-spam-high-risk-delivery-pool-about.md

Content VSO 591495

* [AIRA] Bot Remediation - dansimp (defender-docs-pr, d365-test8b-dansimp) (#8085)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update email-analysis-investigations.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - deniseb (defender-docs-pr, d365-test8b-deniseb) (#8086)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update authorship information in documentation

* Change section title to 'Related content'

Updated section title and added related content links.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Denise Vangel-MSFT <deniseb@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [1/2] (#8087)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Fix formatting in air-report-false-positives-negatives.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-e) [2/2] (#8090)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - unowned (defender-docs-pr, em-test8d) (#8091)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* fix(COPY-EDIT): editorial (#8089)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* CFA article updates (#8149)

* Configure controlled folder access

* Added Windows Security app procedures

And removed them elsewhere

* CFA overview article rename

* CFA

* CFA Overview

* Delete customize-controlled-folders.md

* Removed CFA article from MDB

And also cleaned up ASR/ASR rule references and links, including any Intune procedure links.

* Link and link title updates for CFA

* Update address-unwanted-behaviors-mde.md

* New monitor CFA article

Remnants of the old evaluate CFA article + Windows event viewer steps/info from the CFA overview article.

* Copy and Technical edits

* CFA demonstrations

* CFA demos

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* CFA/ASR demo updates

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* Final edits

* Offending file name renames

Per build report

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-c) (#8082)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update address-compromised-users-quickly.md

* Fix formatting of ms.custom metadata in markdown

* Fix formatting of custom metadata in markdown file

* Correct 'ms.custom' formatting in documentation

Fixed formatting of the 'ms.custom' metadata entry.

* Update custom metadata in mdo-portal-permissions.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8053)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* docs(sentinel): add parameterized notebook job guidance

Add steps for defining notebook parameters, refreshing job parameters, and overriding values when running a notebook job manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 11) - NEW SERIES, IGNORE BATCH NUMBER (#7939)

* Docs: soft rebrand Defender XDR to Defender (batch 11)

Replace 'Defender XDR' and 'Microsoft Defender XDR' with 'Defender' and
'Microsoft Defender' in body text of 20 advanced hunting schema and
feature articles, per Microsoft Defender branding guidelines.

Preserved unchanged:
- appliesto metadata fields
- [!INCLUDE references
- ms.service and other metadata fields
- Link display text referencing external page titles
- URL paths and fragments

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back change.

Updated description to specify Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-2) (#8016)

* Docs: soft rebrand Defender XDR → Defender (batch 612-2)

Update 18 advanced hunting files to replace 'Defender XDR' and
'Microsoft Defender XDR' with 'Defender' and 'Microsoft Defender'
in body text per branding guidelines. Protected references
(metadata, includes, API names, historical records, plugin names)
are left unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

* Roll back change.

* Roll back change.

Updated the description to include 'XDR' in the title.

* Roll back change.

* Roll back changes.

Updated references to Microsoft Defender XDR in the document.

* Roll back changes.

Updated references from Microsoft Defender for Endpoint to Microsoft Defender XDR in the migration guide.

* Roll back changes.

* Roll back changes.

Updated title and references to reflect Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-9) (#8030)

* Docs: soft rebrand Defender XDR → Defender (batch 612-9)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 10 files. 1 file had no eligible changes (all XDR refs were protected product names).

Protected references preserved: metadata fields, [!INCLUDE] lines, image alt text, historical changelog entries in whats-new.md, API endpoint names, external blog post titles, 'Defender Experts for XDR' product name, XDR capability descriptions (XDR solution, XDR tools, XDR/SIEM).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR, including changes to titles and descriptions throughout the content.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix typo in Microsoft Defender XDR description

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Fix directory path and update checksum commands (#8334)

Command errors caused by folder structure or incorrect quotation/space within a zip file.

* Clarify prerequisites for attack disruption exclusions based on Unified RBAC state (#8276)

Split the Prerequisites section into Device and Identity exclusion
permissions, showing the required roles when Unified RBAC is enabled
versus disabled. Cross-link to Unified RBAC activation and custom
permissions docs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#8341)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update value-data-connectors.md with onboarding notes (#8254)

* Update value-data-connectors.md with onboarding notes

Added note about device onboarding requirements and limitations.

* Apply suggestion from @DebLanger

* Update date and permissions in get-machines.md (#8344)

Updated the date and permissions section in the API documentation.

* wi-589516: Remove '| Microsoft Docs' suffix from title metadata (#8255)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>

* Update email post delivery events documentation

* Learn Editor: Update fixed-reported-inaccuracies.md (#8308)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA (#8354)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA

* Updating what's new

* Removing preview note

* Docs: soft rebrand Defender XDR → Defender (batch 2) (#8191)

* Docs: soft rebrand Defender XDR → Defender (batch 2)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR'
with 'Defender' in eligible locations per branding guidelines.

Files updated:
- critical-asset-management.md (1 replacement)
- get-started-exposure-management.md (4 replacements)
- prerequisites.md (3 replacements)
- whats-new.md (0 - all references in historical What's New entries)

Preserved XDR references in:
- Bold UI navigation paths (prerequisites.md line 67)
- Historical What's New entries (whats-new.md lines 179, 310)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 13) (#7941)

* docs: soft rebrand Defender XDR → Defender (batch 13)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers (#8350)

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers

- Add limitation note to Security findings (Preview) component in AKS, EKS, and GKE tabs
  stating it cannot be enabled through Azure Policy and must be toggled in plan Settings
- Rename 'Security findings' to 'Security findings (Preview)' for accuracy
- Remove 'This article explains' from opening line per style guide

Addresses US585115 / IcM 662676555 / CxE WI 19929

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestions from code review

Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add identity assessment key mappings to transition reference article (#8351)

* Add identity assessment key mappings to transition reference article

Replace placeholder in Microsoft Defender for Identity section with
assessment key mapping table for 5 guest/disabled account assessments.
Uses 'assessment' terminology per Roy's guidance.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8050)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8048)

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentinel-mberdugo-02) (#8047)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title from 'Next steps' to 'Related content'

* Fix formatting of title in integration guide

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Cloud security reporting GA (#8267)

* Cloud security reporting GA: remove preview, add release note and card customization

- Remove (Preview) from title and H1 in cloud-security-reporting.md
- Remove preview features prerequisite
- Add card customization capability
- Add June 30 GA release note entry

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add customize cards section with screenshots to cloud reporting article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Clarify that card customization is only for cards labeled Customizable

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add migration guidance for Sentinel incident creation rules to Defender alert grouping (#7952)

* Add Sentinel-to-Defender alert grouping migration guidance

* Relocate Sentinel migration article to unified-secops docset

* Update migration images and include restored xdr article copy

* Remove duplicate defender-xdr migration article copy

* Update image alt text for incident correlation migration doc

* Fix validation issues for incident correlation migration docs

* Fix broken migration link and update image references

* israel review

* Fix PR validation issues for links, metadata, and image naming

* Fix broken unified secops migration links

* Remove image from incident creation migration article

* Remove unused onboarding image file

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Revert to correct cross-docset URL link for new migrate-sentinel article

* Revert to correct cross-docset URL link for new migrate-sentinel article

---------

Co-authored-by: Guy Wild <98332688+guywi-ms@users.noreply.github.com>

* Clarify DlpInfo description in deviceinfo table

Updated DlpInfo description to clarify its content and added a reference link for further information.

* GA multicloud recommendations June 30: release notes, score impact, new tag docs, reference updates (#8275)

* Docs: GA multicloud recommendations June 30 - score impact, new tag, ref updates

- Add June 30 GA release note for expanded multicloud coverage
  (~150 recommendations, ~90 resource types, score impact)
- Add GA/Preview rows to recommendations release notes
- Document 'New' tag (30-day window), change log, and portal banner
  in review-security-recommendations.md (both portal pivots)
- Add Secure Score impact callout to secure-score-security-controls.md
- Remove (Preview) from 217 multicloud recommendations across 6
  reference files (networking, data, identity-access, app-services,
  compute, container)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix: restore deleted category tabs and select step in review-security-recommendations.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix DlpInfo reference link in deviceinfo-table.md

Updated the reference link for DlpInfo properties to ensure it points to the correct documentation.

* Add event-driven response guide for Defender for Storage malware scanning (#8345)

- Expand Event Grid setup walkthrough in configure-malware-scan article with 3-step process
- Add 3 Azure Functions templates: quarantine, auto-delete, and alert/notification
- Add sample payloads for No threats found and Not Scanned result types
- Add event delivery troubleshooting section covering permissions, networking, and subscription validation
- Add Event-driven response feature bullet to introduction article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Align identity risk score GA heading with what's-new convention

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Widespread Local Admin predefined classification rules (#8289)

* Add Widespread Local Admin classification rules and release note

- Add three new Identity classification rules to predefined classifications:
  Widespread Local Admin on Servers (High), Widespread Local Admin on
  Workstations (High), and Widespread Local Admin on Servers and
  Workstations (Very High)
- Add June 2026 release note entry for the new Identity classifications

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Reorder Widespread Local Admin rules and add dependency note

- Reorder to: Servers, Workstations, Servers and Workstations in both files
- Add note to 'Servers and Workstations' rule indicating it relies on
  the Servers and Workstations classifications

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* wi-586653-USX-transition-docs-improvements-CxE (#8183)

* wi-586653-USX-transition-docs-improvements-CxE

Changes:
 Investigation row (line 50):

   - Added hyperlinks to "Attack story" and "incident graph" � /defender-xdr/investigate-incidents#attack-story
   - Added blast radius analysis mention with link � /defender-xdr/investigate-incidents#blast-radius-analysis
   - Removed "(Sentinel Graph)" label � the actual feature name is just "incident graph"

  Security Copilot row (line 58):

   - Added "autonomous Security Copilot agents" with link � /defender-xdr/security-copilot-agents-defender
   - Added "threat hunting" agent link � /defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent
   - Added "Included capacity for E5/E7 customers" with link � /copilot/security/security-copilot-inclusion
   - Updated Benefits column: "agentic defense" added

* mto - playbooks and lighthouse

 Changes in sentinel/move-to-defender.md:

   - Added IMPORTANT callout clarifying that MTO doesn't replace Azure Lighthouse (gap 10), listing operations that still require Lighthouse
   - Added note that playbooks can't be distributed through MTO content distribution, with CI/CD workaround (gap 11)

* Update move-to-defender.md

Changes in sentinel/move-to-defender.md:

 - Gap 13 (SCU inclusion): Added E5/E7 included Security Copilot capacity mention with link to the existing NOTE callout about transition costs
 - Gap 15 (Investigation visuals): Added paragraph about attack story, incident graph, and blast radius analysis with links, under "Update incident triage processes"
 - Gap 8 (AAD/UEBA): Added note at end of UEBA section explaining that Sentinel UEBA signals feed into automatic attack disruption after transition, with link
 - Gap 12 (SOC Optimization): Added new "Use SOC optimization recommendations" subsection explaining cross-service vs Sentinel-only differences, with links to docs and API

* fix build error

* added "prioritize containment actions"

* small tweaks

* corrections

* Update move-to-defender.md

* Alert trigger scope limitation updates

1. In create-manage-use-automation-rules.md, after the trigger table, a NOTE now says:

“In the Defender portal, alert triggers work only on Microsoft Sentinel alerts,” and links to Enhanced Alert Trigger (Public Preview).

2. Updated core automation rules limitation text to include the solution path:

In automate-incident-handling-with-automation-rules.md, the NOTE under alert-triggered automation now explicitly says Defender XDR alert-triggered automation isn’t available in the Defender portal and points to Enhanced Alert Trigger (Public Preview).

3. Standardized migration/transition include messaging so the limitation points to the preview workaround:

In automation-in-defender.md, the “Automation rules with alert triggers” row now includes the limitation plus a direct link to Enhanced Alert Trigger (Public Preview).

4. Made the destination feature explicitly labeled as preview:

In generate-playbook.md, the section heading was updated to “Enhanced alert trigger (Public Preview).”

* Bookmark deprecation

* 5–10 minute batching window

updated note in sentinel\automate-incident-handling-with-automation-rules.md

* data lake - regional data processing limitation

* mutli-tenant: Playbooks not distributable via MTM

* Multitenant operations (MTO) and Azure Lighthouse

* PR build errors + bookmarks- advanced hunting

* Adjusting spacing between tables

* Clarify bookmarks note

* Removed "Public" from "Public Preview"

* bookmarks update

* bookmarks tweak

* 5-10 min lag - formatting

* ueba update

* Update advanced-hunting-microsoft-defender.md

* Remove (Preview) from enhanced triggers

Confirmed with PM Guy Shmeltzer, enhanced triggers are already GA

* Move MTO vs Azure Lighthouse content to separate branch/PR (wi-592684)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move WIP content to part-2 branch; revert unresolved items to main

Removes still-in-progress content (AAD context, E5/E7 Copilot capacity, SOC
optimization subsection, regional workspace support, MTM playbook distribution)
from the publishing branch. Adaptations reverted to main; pure additions removed.
Approved content retained.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken link to migrate-sentinel-incident-creation-rules-alert-grouping

Correct the docset path from /unified-secops/ to /unified-secops-platform/ where
the target article actually resides.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken migrate-rules link in Defender-Sentinel integration article

Correct /unified-secops/ to /unified-secops-platform/ for the migrate article path.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* mshta recommendation - GA

* Add AI agent predefined classification rules (#8317)

- Add new AI agent category to predefined classifications
- Add Executive-Sponsored AI Agent rule (Medium criticality)
- Add AI Agent with Privileged Business System Write Access rule (Medium criticality)
- Add what's new entry for June 2026

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Eliminate redundant click-through procedures in Defender for Endpoint content (1 of 2) (#8339)

* Eliminate redundant click-through procedures in Defender for Endpoint content

* Fix bullets

* Add docs

* Add files

* Add files

* Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2) (#8359)

* Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2)

* Fix warning

* Update release-notes.md (#8365)

* Learn Editor: Update release-notes.md

* Learn Editor: Update release-notes.md

* Update support-matrix-defender-for-cloud.md (#8364)

* Learn Editor: Update support-matrix-defender-for-cloud.md

* Learn Editor: Update support-matrix-defender-for-cloud.md

* Update regional-availability.md (#8363)

* Learn Editor: Update regional-availability.md

* Learn Editor: Update regional-availability.md

* Add UAE North and UAE Central support for Defender for APIs and API security posture management in DCSPM (#8325)

* Add UAE North and UAE Central support for Defender for APIs and API security posture

Microsoft Defender for APIs and API security posture management in Defender CSPM now support the UAE North and UAE Central Azure regions. Update region lists and add a release note for the June 29, 2026 release.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 23) (#7959)

* docs: soft rebrand Defender XDR → Defender (batch 23)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 18) (#7954)

* docs: soft rebrand Defender XDR → Defender (batch 18)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 21) (#7957)

* docs: soft rebrand Defender XDR → Defender (batch 21)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Address build warning.

Added a section on required permissions for Defender for Identity in Microsoft Defender.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "[AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentine…" (#8373)

This reverts commit 7138bc781bf3c32c0099bd2c8b5d60ccaa4f1ab9.

* Revert "fix(COPY-EDIT): editorial (#8048)" (#8374)

This reverts commit b7e81b8cbc50a5adb4b767a180ec86ce16857156.

* Revert "fix(COPY-EDIT): editorial (#8050)" (#8375)

This reverts commit d054038bbad2c30c31aa5a112a18cdfffd9f9f1f.

* Add Simple Flows automation rules article (AB#570290) (#7690)

* Update Simple Flows action references table and TOC

* Fix broken bookmark in permissions link

The target article doesn't have a #permissions-for-automation-rules anchor.
Drop the anchor and link to the article generally.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Dissolve Known limitations section into action context

Move each limitation next to the action it constrains:
- Email-wide constraints (fixed template, fixed sender, no CC/BCC, no audit log) consolidated into a single NOTE callout after the Actions reference table.
- Assign SLA Policy: existing-policy caveat appended to the action's Behavior cell.
- 10-tasks-per-rule limit was already documented in the Add Task row, so the duplicate bullet is dropped.

Also align Update Case field labels with the feature spec (Email recipients, Grace period).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Cross-link Simple Flows from existing automation-rules articles

Add NOTE callouts pointing to the new Simple Flows article from:
- automate-incident-handling-with-automation-rules.md (Triggers + Actions sections)
- create-manage-use-automation-rules.md (Choose your trigger + Add actions sections)

Each callout is gated on Defender-portal onboarding to match the new feature's availability.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply review must-fixes: title preview tag, capitalization, link text, missing space

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove em-dashes from prose; convert two cross-link NOTEs to inline

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Expand SOC/SLA/SOAR acronyms; reorder What is before Prerequisites

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add portal navigation to Examples 2-4; clearer phrasing on case-trigger cross-link

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply Guy's feedback: broaden to Defender portal scope; drop Assign SLA Policy; new examples; case custom fields

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Drop SLA examples; keep Update Alert and Add Task examples only

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Simplify rule-layering tip

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove SLA Exceeded Email action and update examples

Removed the 'Send Case SLA Exceeded Email' action from the automation rules table and updated example instructions for creating automation rules.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Guy Wild <98332688+guywi-ms@users.noreply.github.com>
Co-authored-by: Dennis Rea <v-denrea@microsoft.com>

* Chrisda to Main (#8377)

* Update attack-surface-reduction-rules-reference.md

Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'

* Update attack-surface-reduction-rules-overview.md

Consistency updates

* ASR rules report screenshot updates

More data

* Remove A3 from E3 gets MDO P1 refs

Per request

* Added Teams to report suspicious

* Update outbound-spam-high-risk-delivery-pool-about.md

Content VSO 591495

* Update anti-phishing-policies-about.md

Per IM request

* Approval update (#8379)

* URBAC by default updates (#7804)

* URBAC by default updates

* URBAC edits/additions per PM feedback

* Fix renamed Defender portal icon links after merging main

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update configure-unified-rbac-for-mdo.md

Removed Sample deployment models section per PM request prior to publish

* Copy edits

* File rename per build report

* File rename per build report

* File rename per build report

* File rename per build report

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* WI593231 malware detection GA

* Update triage agents to use least-privilege email permission (#8034)

* Update triage agents to use least-privilege email permission

Replace the broad 'Email & collaboration content (read)' permission with
the more limited 'Email & collaboration content: Emails associated with
alerts (read)' permission in the Phishing Triage Agent and Security Alert
Triage Agent docs. This restricts agent access to only emails associated
with alerts, improving security posture.

Also adds a what's-new entry for June 2026.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Replace permission screenshots with updated UI showing least-privilege option

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* WI593234-agentless scanning vm update

* Add get started article for Defender security for AI agents (#8296)

* Add get started article for Defender security for AI agents

Create get-started-defender-security-for-ai.md covering the onboarding
flow: enabling data collection, connecting Microsoft 365 connector,
and onboarding Copilot Studio real-time protection. Add TOC entry.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add screenshots to Defender security for AI get started article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove redundant Power Platform integration URL screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* updates

* Update security-for-ai-setup-checklist.png

* Update get-started-defender-security-for-ai.md

* Update get-started-defender-security-for-ai.md

* Split AI agent detection/protection doc into detect-investigate and real-time protection pages

- Repurpose ai-agent-detection-protection.md to focus on detection and investigation
- Add ai-agent-real-time-protection.md covering RTP, policy rules, and prompt evidence
- Add real-time protection policy experience screenshots
- Update TOC, cross-links, and Next steps in related articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Group AI agent security articles under 'Protect AI agents' subnode

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename real-time protection TOC node to 'Block agent threats in real time'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Order real-time protection before detect and investigate in agent security TOC

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Align agent security articles: standardize AgentsInfo table, RTP policy path, remove Preview labels

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix legacy table name to AIAgentsInfo and remove appliesto block from inventory article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename real-time protection node and move it after Get started in agent security TOC

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove temporary Defender for Cloud Apps onboarding notes from agent security articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rework agent onboarding to drop MDA framing: move prereqs, remove extended-detection section, point Copilot Studio to Get started

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Remove Agent 365 subscription notes and preview-feature prerequisites from agent articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add BehaviorInfo table to Advanced Hunting tables for AI agent investigation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update get-started prerequisites to Agent 365 onboarding

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename get-started article to 'Enable security for AI agents using Microsoft Defender'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Refine get-started wording and restructure connect data sources section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update Microsoft 365 connector setup steps and add components screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Describe Microsoft 365 connector components in get-started article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Microsoft Entra users/groups and Microsoft 365 files connector components

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Link enable file monitoring step for Microsoft 365 files component

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.…
learn-build-service-prod Bot added a commit that referenced this pull request Aug 7, 2026
* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Updated published docs with latest contributions (#8824)

* Update identity remediation actions for unified multi-connector support

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Make identity actions section generic and reference remediation actions page

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Use comma-separated values for supported identity sources column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Update roles table with connector columns for identity providers and SaaS apps

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add MDA roles for SaaS apps column and SOC Identity Responder role

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Remove Deactivate and Set account risk actions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add Entra ID roles for Force password change action

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add SOC Identity Responder to Entra ID column for response actions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Reference required permissions page for identity provider column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add SOC Identity Responder to Defender for Identity response actions permissions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Clarify identity actions span connectors across on-prem, Entra ID, IAM, and SaaS

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Trim identity actions view details to account settings only

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Fix Supported actions table: remove stray SOC role and link column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Remove SOC Identity Responder from Enable action (not supported)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Learn Editor: Update alerts-containers.md

* Learn Editor: Update alerts-containers.md

* Remove AI Agent write access classification

Removed the description for AI agents with privileged business system write access from the predefined classifications section.

* Learn Editor: Update ai-threat-protection.md

* Move account correlation rules under Settings (#8793)

* Move account correlation rules under settings

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Adjust account correlation navigation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Use full account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Restore original account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Resize account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

---------

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

---------

Co-authored-by: izauer-bit <76057672+izauer-bit@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: EyalGur74 <160857568+EyalGur74@users.noreply.github.com>
Co-authored-by: Sapir Schneider <296893019+SapirSchneiderService@users.noreply.github.com>
Co-authored-by: Liran Levy <309411196+liran-levy3@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* OOB publish for sync PR (#8976)

* Docs: soft rebrand Defender XDR → Defender (batch 612-6) (#8027)

* Docs: soft rebrand Defender XDR → Defender (batch 612-6)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 20 files. Protected references (metadata, includes, UI navigation, image alt text, detection source names, acronym definitions, XDR detection engine names) are preserved.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back Changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix conflict.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/defender-docs (branch public) (#7591)

* Add custom graph cost management link in graph charges section

* Update mdb-faq.yml

Updating public documentation because numerous support cases have been opened due to documentation being unclear. Government customers are not included in this section and should be clarified for customers when trying to understand what licensing is required.

* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#525)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Ofer Schreiber <ofer@bigpanda.io>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update advanced-hunting-emailattachmentinfo-table.md (#307)

Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. `.exe`) while the field is actually a file content type (e.g. `txt;text` or `email;mime` or `png`).

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update advanced-hunting-take-action.md with query reference (#406)

* Update advanced-hunting-take-action.md with query reference

Added Kusto query reference for enabling 'Submit to Microsoft' and 'Initiate automated investigation'. To make it more clear after it was raised in the community

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Update manage-event-based-updates-microsoft-defender-antivirus.md (#345)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update with the correct GPO setting name (#365)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* MDB: Update references to the onboarding (#377)

* fix: MDB, update onboarding, rename MAM to WIP

Azure Portal has slowly but progressively been moved to Entra admin center: Update the URL and the actual naming in the portal.

MAM isn't mentioned it seems to be replaced by Windows Information Protection in the same screen.

* fix: Further replace MAM occurrences by WIP 

MAM wording has been removed from both the old Azure portal, as well as in Entra admin center.

* fix: MDB, add updated screenshot MDM and WIP user scopes

While the structure is mostly unchanged, add new screenshot that includes current namings and same design of selector / radio buttons.

* MDB: Include updated screenshot

Include updated screenshot and update description of the picture.

* MDB: Delete old screenshot of MEM/MAM user scope settings

New picture was added with new name, this one is now obsolete.

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Change MDEConfig.txt to DefenderDTconfig.txt (#418)

"DefenderDT.exe -makeconfig" crates a file named DefenderDTconfig.txt instead of MDEConfig.txt

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Update configure-network-connections-microsoft-defender-antivirus.md (#448)

Fixing broken link for https://learn.microsoft.com/en-us/windows/privacy/manage-windows-1709-endpoints#windows-update

No longer works because of ham-fisted MS redirects.

* Update advanced-hunting-microsoft-defender.md (#343)

Add to "known Issues":
When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting.

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Fix grammar in Teams block entry instructions (#496)

* Fix grammar in Teams block entry instructions

Blocking a domain does not block the Teams meeting invitation itself. Blocking a domain will remove the user from the Teams meeting chat after the meeting ends. The current documentation (Teams Meetings) may be misleading as to suggest that it affects all meetings.

* Fix grammar in Teams block entry instructions

Corrected grammatical errors in the block entry explanation.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Clarify instructions for running Client Analyzer shipped version  (#498)

* Clarify instructions for running Client Analyzer shipped version in live response

Adjust the format which is clearer for binary version and python version separately.

* Update run-analyzer-linux.md

* Fix formatting and wording in run-analyzer-linux.md

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Update faqs-on-tamper-protection.yml (#532)

Remove bracket so link properly connects to target URL

* Update quarantine-shared-mailbox-messages.md (#528)

* Update quarantine-shared-mailbox-messages.md

Updated wording for clarity and expanded scope to include both shared and user mailboxes.

* Update quarantine management instructions and date

Updated the date for the document and refined the instructions for accessing quarantined messages in shared mailboxes.

* Update shared mailbox quarantine management instructions

Clarified that automapping is no longer required for managing quarantined messages in shared mailboxes. Updated conditions for accessing quarantined messages.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Resolve syncing conflicts from repo_sync_working_branch to public (#529)

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-04) (#8059)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix fictional bookmarks AIRA created

Removed redundant options for enabling UEBA and streamlined the text.

* Remove bookmark to nonexistent content

Removed redundant sentence in the UEBA documentation.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update release-notes-recommendations-alerts.md

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [2/2] (#8088)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix metadata for PIM in MDO configuration document

* Fix metadata for safe attachments configuration doc

* Update ms.custom metadata in documentation

* Fix formatting in submissions admin review document

* Fix formatting for ms.custom in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-06) (#8061)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix bad AIRA edit

Updated section header from 'Next steps' to 'Next step'.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b5) (#8096)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting of ms.custom metadata in document

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8060)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8062)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8072)

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8095)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Clarify that the Risky IP address category is dynamic (#8198)

* Clarify that the Risky IP category is dynamic and can expire

Add a note explaining that the Risky category is assigned automatically
based on threat intelligence and is removed if no further malicious
activity is detected. All other categories are assigned manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: AbbyMSFT <88824859+AbbyMSFT@users.noreply.github.com>

* Apply suggestion from @AbbyMSFT

* Apply suggestion from @AbbyMSFT

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* new onboarding (#7970)

* new onboarding

* updates

* updates

---------

Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-usp-test8a-mberdugo) (#8077)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Remove AIRA-duplicated ai-usage metadata

Removed 'ai-usage' line from the document header.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Update approval functionality (#8303)

* Update approval functionality (#8304)

* docs(sentinel): add parameterized notebook jobs

Adds overview and detailed guidance for parameterized notebook jobs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* WI591424: GA transition for serverless containers docs

* Restore historical preview note and keep separate GA release note

* Move June 25 GA note to top of table and section list

* Document Registry access requirement for full Serverless Containers features

* Update defender-for-cloud/release-notes.md

* Update defender-for-cloud/release-notes.md

* Mark Serverless Containers as supported in Defender portal

* Move serverless containers GA date to July 1

* Place July 1 release note under July table

* Set July 1 ms.date across remaining PR pages

* Version 26.1.1 (#8316)

* Version 26.1.1

* Fixes

* Mapping updates to transition from grouped to individual recommendations (#8151)

* Transition from grouped to individual recommendations

* Update transition article with end-state classification for deprecated assessments

- Add explanation of 3 end-states (dynamic substitute, static substitute, no substitute)
- Add End-state and New assessment ID columns to all reference tables
- Change 'NA (Static)' to 'Unknown' in Category column for static substitutes (EDR, SQL)
- Mark EDR and SQL rows as static substitutes with [TBD] new assessment IDs
- Fix HostMisconfiguration → HostMisconfigurations per category list
- Mark GitHub security posture management row as [TBD] pending DevOps partner input
- Add placeholder section for Microsoft Defender for Identity (pending partner review)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date and clarify static substitute guidance

- Add July 31, 2026 as the grouped recommendation deprecation date
- Clarify that static substitute recommendations use 'Unknown' category
  and users should filter by assessment ID, not category filter

Per meeting with Roy Hirsch (June 21, 2026)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "Add July 31 deprecation date and clarify static substitute guidance"

This reverts commit c4f487921093d967d968310ed5e2773e07cf3291.

* Update grouped-to-individual recommendations article per Roy Hirsch review

- Remove IcM routing column from all tables (internal-only, not customer-facing)
- Fix ARG query field: securityCategories -> recommendationCategory
- Fix category name: 'Vulnerabilities' -> 'SoftwareUpdate' recommendation category
- Replace 'assessment key/ID' with 'recommendation ID' throughout
- Replace 'grouped assessment' with 'grouped recommendation' throughout
- Remove 'No substitute' end-state (deprecated items not included in this guide)
- Split each product table into Dynamic substitutes and Static substitutes sections
- Simplify table columns: Dynamic (Recommendation | Recommendation ID | Category),
  Static (Recommendation | Recommendation ID | New recommendation ID)
- Remove IcM routing reference from intro tip and reference section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename 'Recommendation category reference' to 'Recommendation transition reference'

Section now covers both dynamic (category-based) and static (recommendation ID-based)
transitions, so 'category reference' was no longer accurate.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date to transition guides

- Add July 31, 2026 deprecation date in transition-grouped-individual-recommendations.md
  (overview callout, adopting section, what you should do now callout)
- Add July 31, 2026 deprecation date in transition-disable-rules-exemptions.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update transition guide with Roy's final feedback

- SQL databases/servers recs: mark as deprecated, replace static substitute table with note and link to full SQL recommendations reference
- Containers: add Azure (c609cf0f) and AWS (682b2595) running container images as dynamic substitutes mapped to SoftwareUpdate
- GitHub security posture mgmt (fd104c01): update [TBD] with link to full DevOps recommendations reference
- Linux secure boot rec (ad50b498): not added (status unknown per Roy)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix SQL recommendations link to point to VA rules mapping article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Replace internal substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply manual edits and re-apply terminology changes

- Remove Secure Score row from comparison table
- Update vulnerability management example description
- Rename old query label and add note before new query
- Remove Secure Score during transition section
- Change EDR recs to deprecated recommendations
- Replace Dynamic/Static substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix terminology: replace 'Dynamic substitutes' with 'Replaced by individual recommendations' in Containers and DevOps sections; fix garbled text and table in Servers deprecated section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix files moved in error (#8310)

* fix files moved in error

* fixes

* [AIRA] Bot Remediation - AbbyMSFT (defender-docs-pr, 20260615-dfi-root-b-r1) (#8073)

* fix(COPY-EDIT): batch

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b3) (#8094)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix ms.custom field formatting in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8074)

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Restructure MDA TOC around customer journey (#7505)

* Restructure MDA TOC around customer journey

Reorganize from feature-based sections to a lifecycle flow:
Deploy > Connect and discover > Assess risk > Control and protect >
Detect threats > Investigate and respond > Stream to SIEM > Manage

Key changes:
- Dissolve app governance silo into relevant phases
- Merge 'View and manage applications' into discovery
- Merge 'Information protection' into 'Control access and protect data'
- Move AI agent protection into discovery section
- Rename SIEM section to clarify outbound direction
- Move operations guide into 'Manage and configure'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename section to 'Investigate and respond to threats'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add PR target instruction to copilot-instructions.md

Ensure PRs are always created against MicrosoftDocs/defender-docs-pr
rather than the fork.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move app governance setup articles to appropriate sections

- 'Turn on app governance' moves into Configuration (it's a config task)
- 'Get started with app governance' moves into 'Discover and manage
  OAuth apps' (it's a product walkthrough, not deployment)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply content audit: move articles to correct lifecycle phases

Based on full-content audit of 35 cross-cutting articles:

Moved to 'Control access and protect data':
- manage-app-permissions.md (renamed to 'Manage OAuth app permissions')
- app-governance-visibility-insights-sensitive-content.md
- governance-discovery.md
- mde-govern.md
- ai-agent-protection.md and real-time-agent-protection (AI agent protection)

Moved to 'Investigate and respond to threats':
- app-governance-anomaly-detection-alerts.md
- app-governance-investigate-predefined-policies.md
- tutorial-flow.md (response automation, not SIEM)

Kept ai-agent-inventory.md in discovery (primary entry point).
AI agent discovery stays in Connect and discover; protection moves
to Control access.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename discovery sections for clarity

- 'Discover cloud apps (shadow IT)' -> 'Discover cloud apps and shadow IT'
- 'Discover and manage OAuth apps' -> 'Discover and manage OAuth apps with app governance'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Restructure MDA TOC: split discover/connect, rename access section

- Split 'Connect and discover apps' into separate 'Discover apps' and
  'Connect apps' sections, with discovery first
- Rename 'Control access and protect data' to 'Manage access and app behavior'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Consolidate app governance articles and clarify OAuth app scope in titles

- Flatten Connect apps TOC node (remove unnecessary intermediate level)
- Consolidate app governance articles:
  - Merge policies overview + get-started + predefined into single overview
  - Merge policies create + manage into single create-and-manage article
  - Merge threat detection overview + get-started + monitor into single article
  - Merge visibility insights overview + get-started into single article
- Update all app governance TOC nodes and article titles to include 'OAuth'
  to distinguish from SaaS app content
- Add redirects for 6 deleted articles
- Fix all internal links to deleted articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken links in index.yml to deleted articles

Update references to consolidated app governance articles that were
deleted upstream.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Resolve PR review blocking issues: typos, casing, and alt-text fixes

- Fix 'polcies' typo in alt-text (app-policies-overview)
- Add graphic-type prefix to two image alt-texts (app-policies-overview)
- Lowercase 'app governance' in alt-text (detect-remediate-overview)
- Remove duplicate 'the' (secure-apps-access-non-graph-api)
- Lowercase three 'app governance' instances (anomaly-detection-alerts)
- Title case 'Zero Trust' (index.yml)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8075)

Remediation for COPY-EDIT.
Files affected: 6

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-usp-test8a-guywi) (#8076)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title and content in mto-requirements.md

Renamed 'Next steps' section to 'Related content' and updated its content.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8078)

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-b) (#8081)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Improve formatting of simulation automation steps

Formatted the configuration steps into a bulleted list for better readability.

* Update attack-simulation-training-training-campaigns.md

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Update ms.custom metadata in connectors-remove-blocked.md

* Refactor ms.custom metadata in documentation

Updated ms.custom metadata to include a list format.

* Update ms.custom formatting in documentation

* Update ms.custom format in preset-security-policies.md

* Update quarantine-admin-manage-messages-files.md

* Fix formatting of ms.custom property in markdown

* Update ms.custom metadata format in markdown file

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* WI590578-table-insights (#8265)

* WI590578-table-insights

* quality fixes

* additional work

* updated conceptual page

* page quality fixes

* Refine Table insights guidance and restore Data Lake terminology

* Update manage-table-tiers-retention.md

* fixes to instructions

* Update manage-table-tiers-retention.md

* quality fixes

* fix

* fix title

* small fixes

* small fixes

* fix based on Nikita's comment

actually I realized there is one more change when in Whats new section when you click on tables, you can see data sources in side drawer.

* fixing broken list

---------

Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-d) (#8083)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting for ms.custom in alert policies document

* Fix formatting for ms.custom in audit log document

* Fix formatting of ms.custom in documentation

* Fix formatting in connection filter policies document

* Fix formatting in connectors-detect-respond-to-compromise.md

* Remove section for new Microsoft 365 administrators

Removed unnecessary section for new Microsoft 365 administrators and related content. There were no links or anything of value. It was essentially an ad, and even that ad didn't link to anything.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Document AI agent awareness for Entra ID service principals

- Add Used by AI agents (Preview) column to NHI details table
- Add Used by AI agents (Preview) stat to NHI insight cards
- Add what's-new entry for AI agent visibility

Work item: 591169

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Chrisda to Main (#8323)

* Update attack-surface-reduction-rules-reference.md

Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'

* Update attack-surface-reduction-rules-overview.md

Consistency updates

* ASR rules report screenshot updates

More data

* Remove A3 from E3 gets MDO P1 refs

Per request

* Added Teams to report suspicious

* Update outbound-spam-high-risk-delivery-pool-about.md

Content VSO 591495

* [AIRA] Bot Remediation - dansimp (defender-docs-pr, d365-test8b-dansimp) (#8085)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update email-analysis-investigations.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - deniseb (defender-docs-pr, d365-test8b-deniseb) (#8086)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update authorship information in documentation

* Change section title to 'Related content'

Updated section title and added related content links.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Denise Vangel-MSFT <deniseb@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [1/2] (#8087)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Fix formatting in air-report-false-positives-negatives.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-e) [2/2] (#8090)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - unowned (defender-docs-pr, em-test8d) (#8091)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* fix(COPY-EDIT): editorial (#8089)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* CFA article updates (#8149)

* Configure controlled folder access

* Added Windows Security app procedures

And removed them elsewhere

* CFA overview article rename

* CFA

* CFA Overview

* Delete customize-controlled-folders.md

* Removed CFA article from MDB

And also cleaned up ASR/ASR rule references and links, including any Intune procedure links.

* Link and link title updates for CFA

* Update address-unwanted-behaviors-mde.md

* New monitor CFA article

Remnants of the old evaluate CFA article + Windows event viewer steps/info from the CFA overview article.

* Copy and Technical edits

* CFA demonstrations

* CFA demos

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* CFA/ASR demo updates

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* Final edits

* Offending file name renames

Per build report

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-c) (#8082)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update address-compromised-users-quickly.md

* Fix formatting of ms.custom metadata in markdown

* Fix formatting of custom metadata in markdown file

* Correct 'ms.custom' formatting in documentation

Fixed formatting of the 'ms.custom' metadata entry.

* Update custom metadata in mdo-portal-permissions.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8053)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* docs(sentinel): add parameterized notebook job guidance

Add steps for defining notebook parameters, refreshing job parameters, and overriding values when running a notebook job manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 11) - NEW SERIES, IGNORE BATCH NUMBER (#7939)

* Docs: soft rebrand Defender XDR to Defender (batch 11)

Replace 'Defender XDR' and 'Microsoft Defender XDR' with 'Defender' and
'Microsoft Defender' in body text of 20 advanced hunting schema and
feature articles, per Microsoft Defender branding guidelines.

Preserved unchanged:
- appliesto metadata fields
- [!INCLUDE references
- ms.service and other metadata fields
- Link display text referencing external page titles
- URL paths and fragments

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back change.

Updated description to specify Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-2) (#8016)

* Docs: soft rebrand Defender XDR → Defender (batch 612-2)

Update 18 advanced hunting files to replace 'Defender XDR' and
'Microsoft Defender XDR' with 'Defender' and 'Microsoft Defender'
in body text per branding guidelines. Protected references
(metadata, includes, API names, historical records, plugin names)
are left unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

* Roll back change.

* Roll back change.

Updated the description to include 'XDR' in the title.

* Roll back change.

* Roll back changes.

Updated references to Microsoft Defender XDR in the document.

* Roll back changes.

Updated references from Microsoft Defender for Endpoint to Microsoft Defender XDR in the migration guide.

* Roll back changes.

* Roll back changes.

Updated title and references to reflect Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-9) (#8030)

* Docs: soft rebrand Defender XDR → Defender (batch 612-9)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 10 files. 1 file had no eligible changes (all XDR refs were protected product names).

Protected references preserved: metadata fields, [!INCLUDE] lines, image alt text, historical changelog entries in whats-new.md, API endpoint names, external blog post titles, 'Defender Experts for XDR' product name, XDR capability descriptions (XDR solution, XDR tools, XDR/SIEM).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR, including changes to titles and descriptions throughout the content.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix typo in Microsoft Defender XDR description

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Fix directory path and update checksum commands (#8334)

Command errors caused by folder structure or incorrect quotation/space within a zip file.

* Clarify prerequisites for attack disruption exclusions based on Unified RBAC state (#8276)

Split the Prerequisites section into Device and Identity exclusion
permissions, showing the required roles when Unified RBAC is enabled
versus disabled. Cross-link to Unified RBAC activation and custom
permissions docs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#8341)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update value-data-connectors.md with onboarding notes (#8254)

* Update value-data-connectors.md with onboarding notes

Added note about device onboarding requirements and limitations.

* Apply suggestion from @DebLanger

* Update date and permissions in get-machines.md (#8344)

Updated the date and permissions section in the API documentation.

* wi-589516: Remove '| Microsoft Docs' suffix from title metadata (#8255)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>

* Update email post delivery events documentation

* Learn Editor: Update fixed-reported-inaccuracies.md (#8308)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA (#8354)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA

* Updating what's new

* Removing preview note

* Docs: soft rebrand Defender XDR → Defender (batch 2) (#8191)

* Docs: soft rebrand Defender XDR → Defender (batch 2)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR'
with 'Defender' in eligible locations per branding guidelines.

Files updated:
- critical-asset-management.md (1 replacement)
- get-started-exposure-management.md (4 replacements)
- prerequisites.md (3 replacements)
- whats-new.md (0 - all references in historical What's New entries)

Preserved XDR references in:
- Bold UI navigation paths (prerequisites.md line 67)
- Historical What's New entries (whats-new.md lines 179, 310)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 13) (#7941)

* docs: soft rebrand Defender XDR → Defender (batch 13)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers (#8350)

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers

- Add limitation note to Security findings (Preview) component in AKS, EKS, and GKE tabs
  stating it cannot be enabled through Azure Policy and must be toggled in plan Settings
- Rename 'Security findings' to 'Security findings (Preview)' for accuracy
- Remove 'This article explains' from opening line per style guide

Addresses US585115 / IcM 662676555 / CxE WI 19929

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestions from code review

Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add identity assessment key mappings to transition reference article (#8351)

* Add identity assessment key mappings to transition reference article

Replace placeholder in Microsoft Defender for Identity section with
assessment key mapping table for 5 guest/disabled account assessments.
Uses 'assessment' terminology per Roy's guidance.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8050)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8048)

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentinel-mberdugo-02) (#8047)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title from 'Next steps' to 'Related content'

* Fix formatting of title in integration guide

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Cloud security reporting GA (#8267)

* Cloud security reporting GA: remove preview, add release note and card customization

- Remove (Preview) from title and H1 in cloud-security-reporting.md
- Remove preview features prerequisite
- Add card customization capability
- Add June 30 GA release note entry

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add customize cards section with screenshots to cloud reporting article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Clarify that card customization is only for cards labeled Customizable

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add migration guidance for Sentinel incident creation rules to Defender alert grouping (#7952)

* Add Sentinel-to-Defender alert grouping migration guidance

* Relocate Sentinel migration article to unified-secops docset

* Update migration images and include restored xdr article copy

* Remove duplicate defender-xdr migration article copy

* Update image alt text for incident correlation migration doc

* Fix validation issues for incident correlation migration docs

* Fix broken migration link and update image references

* israel review

* Fix PR validation issues for links, metadata, and image naming

* Fix broken unified secops migration links

* Remove image from incident creation migration article

* Remove unused onboarding image file

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Revert to correct cross-docset URL link for new migrate-sentinel article

* Revert to correct cross-docset URL link for new migrate-sentinel article

---------

Co-authored-by: Guy Wild <98332688+guywi-ms@users.noreply.github.com>

* Clarify DlpInfo description in deviceinfo table

Updated DlpInfo description to clarify its content and added a reference link for further information.

* GA multicloud recommendations June 30: release notes, score impact, new tag docs, reference updates (#8275)

* Docs: GA multicloud recommendations June 30 - score impact, new tag, ref updates

- Add June 30 GA release note for expanded multicloud coverage
  (~150 recommendations, ~90 resource types, score impact)
- Add GA/Preview rows to recommendations release notes
- Document 'New' tag (30-day window), change log, and portal banner
  in review-security-recommendations.md (both portal pivots)
- Add Secure Score impact callout to secure-score-security-controls.md
- Remove (Preview) from 217 multicloud recommendations across 6
  reference files (networking, data, identity-access, app-services,
  compute, container)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix: restore deleted category tabs and select step in review-security-recommendations.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix DlpInfo reference link in deviceinfo-table.md

Updated the reference link for DlpInfo properties to ensure it points to the correct documentation.

* Add event-driven response guide for Defender for Storage malware scanning (#8345)

- Expand Event Grid setup walkthrough in configure-malware-scan article with 3-step process
- Add 3 Azure Functions templates: quarantine, auto-delete, and alert/notification
- Add sample payloads for No threats found and Not Scanned result types
- Add event delivery troubleshooting section covering permissions, networking, and subscription validation
- Add Event-driven response feature bullet to introduction article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Align identity risk score GA heading with what's-new convention

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Widespread Local Admin predefined classification rules (#8289)

* Add Widespread Local Admin classification rules and release note

- Add three new Identity classification rules to predefined classifications:
  Widespread Local Admin on Servers (High), Widespread Local Admin on
  Workstations (High), and Widespread Local Admin on Servers and
  Workstations (Very High)
- Add June 2026 release note entry for the new Identity classifications

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Reorder Widespread Local Admin rules and add dependency note

- Reorder to: Servers, Workstations, Servers and Workstations in both files
- Add note to 'Servers and Workstations' rule indicating it relies on
  the Servers and Workstations classifications

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* wi-586653-USX-transition-docs-improvements-CxE (#8183)

* wi-586653-USX-transition-docs-improvements-CxE

Changes:
 Investigation row (line 50):

   - Added hyperlinks to "Attack story" and "incident graph" � /defender-xdr/investigate-incidents#attack-story
   - Added blast radius analysis mention with link � /defender-xdr/investigate-incidents#blast-radius-analysis
   - Removed "(Sentinel Graph)" label � the actual feature name is just "incident graph"

  Security Copilot row (line 58):

   - Added "autonomous Security Copilot agents" with link � /defender-xdr/security-copilot-agents-defender
   - Added "threat hunting" agent link � /defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent
   - Added "Included capacity for E5/E7 customers" with link � /copilot/security/security-copilot-inclusion
   - Updated Benefits column: "agentic defense" added

* mto - playbooks and lighthouse

 Changes in sentinel/move-to-defender.md:

   - Added IMPORTANT callout clarifying that MTO doesn't replace Azure Lighthouse (gap 10), listing operations that still require Lighthouse
   - Added note that playbooks can't be distributed through MTO content distribution, with CI/CD workaround (gap 11)

* Update move-to-defender.md

Changes in sentinel/move-to-defender.md:

 - Gap 13 (SCU inclusion): Added E5/E7 included Security Copilot capacity mention with link to the existing NOTE callout about transition costs
 - Gap 15 (Investigation visuals): Added paragraph about attack story, incident graph, and blast radius analysis with links, under "Update incident triage processes"
 - Gap 8 (AAD/UEBA): Added note at end of UEBA section explaining that Sentinel UEBA signals feed into automatic attack disruption after transition, with link
 - Gap 12 (SOC Optimization): Added new "Use SOC optimization recommendations" subsection explaining cross-service vs Sentinel-only differences, with links to docs and API

* fix build error

* added "prioritize containment actions"

* small tweaks

* corrections

* Update move-to-defender.md

* Alert trigger scope limitation updates

1. In create-manage-use-automation-rules.md, after the trigger table, a NOTE now says:

“In the Defender portal, alert triggers work only on Microsoft Sentinel alerts,” and links to Enhanced Alert Trigger (Public Preview).

2. Updated core automation rules limitation text to include the solution path:

In automate-incident-handling-with-automation-rules.md, the NOTE under alert-triggered automation now explicitly says Defender XDR alert-triggered automation isn’t available in the Defender portal and points to Enhanced Alert Trigger (Public Preview).

3. Standardized migration/transition include messaging so the limitation points to the preview workaround:

In automation-in-defender.md, the “Automation rules with alert triggers” row now includes the limitation plus a direct link to Enhanced Alert Trigger (Public Preview).

4. Made the destination feature explicitly labeled as preview:

In generate-playbook.md, the section heading was updated to “Enhanced alert trigger (Public Preview).”

* Bookmark deprecation

* 5–10 minute batching window

updated note in sentinel\automate-incident-handling-with-automation-rules.md

* data lake - regional data processing limitation

* mutli-tenant: Playbooks not distributable via MTM

* Multitenant operations (MTO) and Azure Lighthouse

* PR build errors + bookmarks- advanced hunting

* Adjusting spacing between tables

* Clarify bookmarks note

* Removed "Public" from "Public Preview"

* bookmarks update

* bookmarks tweak

* 5-10 min lag - formatting

* ueba update

* Update advanced-hunting-microsoft-defender.md

* Remove (Preview) from enhanced triggers

Confirmed with PM Guy Shmeltzer, enhanced triggers are already GA

* Move MTO vs Azure Lighthouse content to separate branch/PR (wi-592684)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move WIP content to part-2 branch; revert unresolved items to main

Removes still-in-progress content (AAD context, E5/E7 Copilot capacity, SOC
optimization subsection, regional workspace support, MTM playbook distribution)
from the publishing branch. Adaptations reverted to main; pure additions removed.
Approved content retained.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken link to migrate-sentinel-incident-creation-rules-alert-grouping

Correct the docset path from /unified-secops/ to /unified-secops-platform/ where
the target article actually resides.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken migrate-rules link in Defender-Sentinel integration article

Correct /unified-secops/ to /unified-secops-platform/ for the migrate article path.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* mshta recommendation - GA

* Add AI agent predefined classification rules (#8317)

- Add new AI agent category to predefined classifications
- Add Executive-Sponsored AI Agent rule (Medium criticality)
- Add AI Agent with Privileged Business System Write Access rule (Medium criticality)
- Add what's new entry for June 2026

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Eliminate redundant click-through procedures in Defender for Endpoint content (1 of 2) (#8339)

* Eliminate redundant click-through procedures in Defender for Endpoint content

* Fix bullets

* Add docs

* Add files

* Add files

* Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2) (#8359)

* Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2)

* Fix warning

* Update release-notes.md (#8365)

* Learn Editor: Update release-notes.md

* Learn Editor: Update release-notes.md

* Update support-matrix-defender-for-cloud.md (#8364)

* Learn Editor: Update support-matrix-defender-for-cloud.md

* Learn Editor: Update support-matrix-defender-for-cloud.md

* Update regional-availability.md (#8363)

* Learn Editor: Update regional-availability.md

* Learn Editor: Update regional-availability.md

* Add UAE North and UAE Central support for Defender for APIs and API security posture management in DCSPM (#8325)

* Add UAE North and UAE Central support for Defender for APIs and API security posture

Microsoft Defender for APIs and API security posture management in Defender CSPM now support the UAE North and UAE Central Azure regions. Update region lists and add a release note for the June 29, 2026 release.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 23) (#7959)

* docs: soft rebrand Defender XDR → Defender (batch 23)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 18) (#7954)

* docs: soft rebrand Defender XDR → Defender (batch 18)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 21) (#7957)

* docs: soft rebrand Defender XDR → Defender (batch 21)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Address build warning.

Added a section on required permissions for Defender for Identity in Microsoft Defender.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "[AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentine…" (#8373)

This reverts commit 7138bc781bf3c32c0099bd2c8b5d60ccaa4f1ab9.

* Revert "fix(COPY-EDIT): editorial (#8048)" (#8374)

This reverts commit b7e81b8cbc50a5adb4b767a180ec86ce16857156.

* Revert "fix(COPY-EDIT): editorial (#8050)" (#8375)

This reverts commit d054038bbad2c30c31aa5a112a18cdfffd9f9f1f.

* Add Simple Flows automation rules article (AB#570290) (#7690)

* Update Simple Flows action references table and TOC

* Fix broken bookmark in permissions link

The target article doesn't have a #permissions-for-automation-rules anchor.
Drop the anchor and link to the article generally.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Dissolve Known limitations section into action context

Move each limitation next to the action it constrains:
- Email-wide constraints (fixed template, fixed sender, no CC/BCC, no audit log) consolidated into a single NOTE callout after the Actions reference table.
- Assign SLA Policy: existing-policy caveat appended to the action's Behavior cell.
- 10-tasks-per-rule limit was already documented in the Add Task row, so the duplicate bullet is dropped.

Also align Update Case field labels with the feature spec (Email recipients, Grace period).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Cross-link Simple Flows from existing automation-rules articles

Add NOTE callouts pointing to the new Simple Flows article from:
- automate-incident-handling-with-automation-rules.md (Triggers + Actions sections)
- create-manage-use-automation-rules.md (Choose your trigger + Add actions sections)

Each callout is gated on Defender-portal onboarding to match the new feature's availability.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com…
learn-build-service-prod Bot added a commit that referenced this pull request Aug 31, 2026
* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Updated published docs with latest contributions (#8824)

* Update identity remediation actions for unified multi-connector support

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Make identity actions section generic and reference remediation actions page

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Use comma-separated values for supported identity sources column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Update roles table with connector columns for identity providers and SaaS apps

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add MDA roles for SaaS apps column and SOC Identity Responder role

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Remove Deactivate and Set account risk actions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add Entra ID roles for Force password change action

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add SOC Identity Responder to Entra ID column for response actions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Reference required permissions page for identity provider column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add SOC Identity Responder to Defender for Identity response actions permissions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Clarify identity actions span connectors across on-prem, Entra ID, IAM, and SaaS

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Trim identity actions view details to account settings only

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Fix Supported actions table: remove stray SOC role and link column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Remove SOC Identity Responder from Enable action (not supported)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Learn Editor: Update alerts-containers.md

* Learn Editor: Update alerts-containers.md

* Remove AI Agent write access classification

Removed the description for AI agents with privileged business system write access from the predefined classifications section.

* Learn Editor: Update ai-threat-protection.md

* Move account correlation rules under Settings (#8793)

* Move account correlation rules under settings

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Adjust account correlation navigation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Use full account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Restore original account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Resize account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

---------

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

---------

Co-authored-by: izauer-bit <76057672+izauer-bit@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: EyalGur74 <160857568+EyalGur74@users.noreply.github.com>
Co-authored-by: Sapir Schneider <296893019+SapirSchneiderService@users.noreply.github.com>
Co-authored-by: Liran Levy <309411196+liran-levy3@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* OOB publish for sync PR (#8976)

* Docs: soft rebrand Defender XDR → Defender (batch 612-6) (#8027)

* Docs: soft rebrand Defender XDR → Defender (batch 612-6)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 20 files. Protected references (metadata, includes, UI navigation, image alt text, detection source names, acronym definitions, XDR detection engine names) are preserved.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back Changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix conflict.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/defender-docs (branch public) (#7591)

* Add custom graph cost management link in graph charges section

* Update mdb-faq.yml

Updating public documentation because numerous support cases have been opened due to documentation being unclear. Government customers are not included in this section and should be clarified for customers when trying to understand what licensing is required.

* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#525)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Ofer Schreiber <ofer@bigpanda.io>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update advanced-hunting-emailattachmentinfo-table.md (#307)

Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. `.exe`) while the field is actually a file content type (e.g. `txt;text` or `email;mime` or `png`).

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update advanced-hunting-take-action.md with query reference (#406)

* Update advanced-hunting-take-action.md with query reference

Added Kusto query reference for enabling 'Submit to Microsoft' and 'Initiate automated investigation'. To make it more clear after it was raised in the community

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Update manage-event-based-updates-microsoft-defender-antivirus.md (#345)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update with the correct GPO setting name (#365)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* MDB: Update references to the onboarding (#377)

* fix: MDB, update onboarding, rename MAM to WIP

Azure Portal has slowly but progressively been moved to Entra admin center: Update the URL and the actual naming in the portal.

MAM isn't mentioned it seems to be replaced by Windows Information Protection in the same screen.

* fix: Further replace MAM occurrences by WIP 

MAM wording has been removed from both the old Azure portal, as well as in Entra admin center.

* fix: MDB, add updated screenshot MDM and WIP user scopes

While the structure is mostly unchanged, add new screenshot that includes current namings and same design of selector / radio buttons.

* MDB: Include updated screenshot

Include updated screenshot and update description of the picture.

* MDB: Delete old screenshot of MEM/MAM user scope settings

New picture was added with new name, this one is now obsolete.

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Change MDEConfig.txt to DefenderDTconfig.txt (#418)

"DefenderDT.exe -makeconfig" crates a file named DefenderDTconfig.txt instead of MDEConfig.txt

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Update configure-network-connections-microsoft-defender-antivirus.md (#448)

Fixing broken link for https://learn.microsoft.com/en-us/windows/privacy/manage-windows-1709-endpoints#windows-update

No longer works because of ham-fisted MS redirects.

* Update advanced-hunting-microsoft-defender.md (#343)

Add to "known Issues":
When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting.

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Fix grammar in Teams block entry instructions (#496)

* Fix grammar in Teams block entry instructions

Blocking a domain does not block the Teams meeting invitation itself. Blocking a domain will remove the user from the Teams meeting chat after the meeting ends. The current documentation (Teams Meetings) may be misleading as to suggest that it affects all meetings.

* Fix grammar in Teams block entry instructions

Corrected grammatical errors in the block entry explanation.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Clarify instructions for running Client Analyzer shipped version  (#498)

* Clarify instructions for running Client Analyzer shipped version in live response

Adjust the format which is clearer for binary version and python version separately.

* Update run-analyzer-linux.md

* Fix formatting and wording in run-analyzer-linux.md

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Update faqs-on-tamper-protection.yml (#532)

Remove bracket so link properly connects to target URL

* Update quarantine-shared-mailbox-messages.md (#528)

* Update quarantine-shared-mailbox-messages.md

Updated wording for clarity and expanded scope to include both shared and user mailboxes.

* Update quarantine management instructions and date

Updated the date for the document and refined the instructions for accessing quarantined messages in shared mailboxes.

* Update shared mailbox quarantine management instructions

Clarified that automapping is no longer required for managing quarantined messages in shared mailboxes. Updated conditions for accessing quarantined messages.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Resolve syncing conflicts from repo_sync_working_branch to public (#529)

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-04) (#8059)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix fictional bookmarks AIRA created

Removed redundant options for enabling UEBA and streamlined the text.

* Remove bookmark to nonexistent content

Removed redundant sentence in the UEBA documentation.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update release-notes-recommendations-alerts.md

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [2/2] (#8088)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix metadata for PIM in MDO configuration document

* Fix metadata for safe attachments configuration doc

* Update ms.custom metadata in documentation

* Fix formatting in submissions admin review document

* Fix formatting for ms.custom in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-06) (#8061)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix bad AIRA edit

Updated section header from 'Next steps' to 'Next step'.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b5) (#8096)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting of ms.custom metadata in document

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8060)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8062)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8072)

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8095)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Clarify that the Risky IP address category is dynamic (#8198)

* Clarify that the Risky IP category is dynamic and can expire

Add a note explaining that the Risky category is assigned automatically
based on threat intelligence and is removed if no further malicious
activity is detected. All other categories are assigned manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: AbbyMSFT <88824859+AbbyMSFT@users.noreply.github.com>

* Apply suggestion from @AbbyMSFT

* Apply suggestion from @AbbyMSFT

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* new onboarding (#7970)

* new onboarding

* updates

* updates

---------

Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-usp-test8a-mberdugo) (#8077)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Remove AIRA-duplicated ai-usage metadata

Removed 'ai-usage' line from the document header.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Update approval functionality (#8303)

* Update approval functionality (#8304)

* docs(sentinel): add parameterized notebook jobs

Adds overview and detailed guidance for parameterized notebook jobs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* WI591424: GA transition for serverless containers docs

* Restore historical preview note and keep separate GA release note

* Move June 25 GA note to top of table and section list

* Document Registry access requirement for full Serverless Containers features

* Update defender-for-cloud/release-notes.md

* Update defender-for-cloud/release-notes.md

* Mark Serverless Containers as supported in Defender portal

* Move serverless containers GA date to July 1

* Place July 1 release note under July table

* Set July 1 ms.date across remaining PR pages

* Version 26.1.1 (#8316)

* Version 26.1.1

* Fixes

* Mapping updates to transition from grouped to individual recommendations (#8151)

* Transition from grouped to individual recommendations

* Update transition article with end-state classification for deprecated assessments

- Add explanation of 3 end-states (dynamic substitute, static substitute, no substitute)
- Add End-state and New assessment ID columns to all reference tables
- Change 'NA (Static)' to 'Unknown' in Category column for static substitutes (EDR, SQL)
- Mark EDR and SQL rows as static substitutes with [TBD] new assessment IDs
- Fix HostMisconfiguration → HostMisconfigurations per category list
- Mark GitHub security posture management row as [TBD] pending DevOps partner input
- Add placeholder section for Microsoft Defender for Identity (pending partner review)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date and clarify static substitute guidance

- Add July 31, 2026 as the grouped recommendation deprecation date
- Clarify that static substitute recommendations use 'Unknown' category
  and users should filter by assessment ID, not category filter

Per meeting with Roy Hirsch (June 21, 2026)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "Add July 31 deprecation date and clarify static substitute guidance"

This reverts commit c4f487921093d967d968310ed5e2773e07cf3291.

* Update grouped-to-individual recommendations article per Roy Hirsch review

- Remove IcM routing column from all tables (internal-only, not customer-facing)
- Fix ARG query field: securityCategories -> recommendationCategory
- Fix category name: 'Vulnerabilities' -> 'SoftwareUpdate' recommendation category
- Replace 'assessment key/ID' with 'recommendation ID' throughout
- Replace 'grouped assessment' with 'grouped recommendation' throughout
- Remove 'No substitute' end-state (deprecated items not included in this guide)
- Split each product table into Dynamic substitutes and Static substitutes sections
- Simplify table columns: Dynamic (Recommendation | Recommendation ID | Category),
  Static (Recommendation | Recommendation ID | New recommendation ID)
- Remove IcM routing reference from intro tip and reference section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename 'Recommendation category reference' to 'Recommendation transition reference'

Section now covers both dynamic (category-based) and static (recommendation ID-based)
transitions, so 'category reference' was no longer accurate.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date to transition guides

- Add July 31, 2026 deprecation date in transition-grouped-individual-recommendations.md
  (overview callout, adopting section, what you should do now callout)
- Add July 31, 2026 deprecation date in transition-disable-rules-exemptions.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update transition guide with Roy's final feedback

- SQL databases/servers recs: mark as deprecated, replace static substitute table with note and link to full SQL recommendations reference
- Containers: add Azure (c609cf0f) and AWS (682b2595) running container images as dynamic substitutes mapped to SoftwareUpdate
- GitHub security posture mgmt (fd104c01): update [TBD] with link to full DevOps recommendations reference
- Linux secure boot rec (ad50b498): not added (status unknown per Roy)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix SQL recommendations link to point to VA rules mapping article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Replace internal substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply manual edits and re-apply terminology changes

- Remove Secure Score row from comparison table
- Update vulnerability management example description
- Rename old query label and add note before new query
- Remove Secure Score during transition section
- Change EDR recs to deprecated recommendations
- Replace Dynamic/Static substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix terminology: replace 'Dynamic substitutes' with 'Replaced by individual recommendations' in Containers and DevOps sections; fix garbled text and table in Servers deprecated section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix files moved in error (#8310)

* fix files moved in error

* fixes

* [AIRA] Bot Remediation - AbbyMSFT (defender-docs-pr, 20260615-dfi-root-b-r1) (#8073)

* fix(COPY-EDIT): batch

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b3) (#8094)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix ms.custom field formatting in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8074)

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Restructure MDA TOC around customer journey (#7505)

* Restructure MDA TOC around customer journey

Reorganize from feature-based sections to a lifecycle flow:
Deploy > Connect and discover > Assess risk > Control and protect >
Detect threats > Investigate and respond > Stream to SIEM > Manage

Key changes:
- Dissolve app governance silo into relevant phases
- Merge 'View and manage applications' into discovery
- Merge 'Information protection' into 'Control access and protect data'
- Move AI agent protection into discovery section
- Rename SIEM section to clarify outbound direction
- Move operations guide into 'Manage and configure'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename section to 'Investigate and respond to threats'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add PR target instruction to copilot-instructions.md

Ensure PRs are always created against MicrosoftDocs/defender-docs-pr
rather than the fork.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move app governance setup articles to appropriate sections

- 'Turn on app governance' moves into Configuration (it's a config task)
- 'Get started with app governance' moves into 'Discover and manage
  OAuth apps' (it's a product walkthrough, not deployment)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply content audit: move articles to correct lifecycle phases

Based on full-content audit of 35 cross-cutting articles:

Moved to 'Control access and protect data':
- manage-app-permissions.md (renamed to 'Manage OAuth app permissions')
- app-governance-visibility-insights-sensitive-content.md
- governance-discovery.md
- mde-govern.md
- ai-agent-protection.md and real-time-agent-protection (AI agent protection)

Moved to 'Investigate and respond to threats':
- app-governance-anomaly-detection-alerts.md
- app-governance-investigate-predefined-policies.md
- tutorial-flow.md (response automation, not SIEM)

Kept ai-agent-inventory.md in discovery (primary entry point).
AI agent discovery stays in Connect and discover; protection moves
to Control access.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename discovery sections for clarity

- 'Discover cloud apps (shadow IT)' -> 'Discover cloud apps and shadow IT'
- 'Discover and manage OAuth apps' -> 'Discover and manage OAuth apps with app governance'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Restructure MDA TOC: split discover/connect, rename access section

- Split 'Connect and discover apps' into separate 'Discover apps' and
  'Connect apps' sections, with discovery first
- Rename 'Control access and protect data' to 'Manage access and app behavior'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Consolidate app governance articles and clarify OAuth app scope in titles

- Flatten Connect apps TOC node (remove unnecessary intermediate level)
- Consolidate app governance articles:
  - Merge policies overview + get-started + predefined into single overview
  - Merge policies create + manage into single create-and-manage article
  - Merge threat detection overview + get-started + monitor into single article
  - Merge visibility insights overview + get-started into single article
- Update all app governance TOC nodes and article titles to include 'OAuth'
  to distinguish from SaaS app content
- Add redirects for 6 deleted articles
- Fix all internal links to deleted articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken links in index.yml to deleted articles

Update references to consolidated app governance articles that were
deleted upstream.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Resolve PR review blocking issues: typos, casing, and alt-text fixes

- Fix 'polcies' typo in alt-text (app-policies-overview)
- Add graphic-type prefix to two image alt-texts (app-policies-overview)
- Lowercase 'app governance' in alt-text (detect-remediate-overview)
- Remove duplicate 'the' (secure-apps-access-non-graph-api)
- Lowercase three 'app governance' instances (anomaly-detection-alerts)
- Title case 'Zero Trust' (index.yml)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8075)

Remediation for COPY-EDIT.
Files affected: 6

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-usp-test8a-guywi) (#8076)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title and content in mto-requirements.md

Renamed 'Next steps' section to 'Related content' and updated its content.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8078)

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-b) (#8081)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Improve formatting of simulation automation steps

Formatted the configuration steps into a bulleted list for better readability.

* Update attack-simulation-training-training-campaigns.md

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Update ms.custom metadata in connectors-remove-blocked.md

* Refactor ms.custom metadata in documentation

Updated ms.custom metadata to include a list format.

* Update ms.custom formatting in documentation

* Update ms.custom format in preset-security-policies.md

* Update quarantine-admin-manage-messages-files.md

* Fix formatting of ms.custom property in markdown

* Update ms.custom metadata format in markdown file

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* WI590578-table-insights (#8265)

* WI590578-table-insights

* quality fixes

* additional work

* updated conceptual page

* page quality fixes

* Refine Table insights guidance and restore Data Lake terminology

* Update manage-table-tiers-retention.md

* fixes to instructions

* Update manage-table-tiers-retention.md

* quality fixes

* fix

* fix title

* small fixes

* small fixes

* fix based on Nikita's comment

actually I realized there is one more change when in Whats new section when you click on tables, you can see data sources in side drawer.

* fixing broken list

---------

Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-d) (#8083)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting for ms.custom in alert policies document

* Fix formatting for ms.custom in audit log document

* Fix formatting of ms.custom in documentation

* Fix formatting in connection filter policies document

* Fix formatting in connectors-detect-respond-to-compromise.md

* Remove section for new Microsoft 365 administrators

Removed unnecessary section for new Microsoft 365 administrators and related content. There were no links or anything of value. It was essentially an ad, and even that ad didn't link to anything.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Document AI agent awareness for Entra ID service principals

- Add Used by AI agents (Preview) column to NHI details table
- Add Used by AI agents (Preview) stat to NHI insight cards
- Add what's-new entry for AI agent visibility

Work item: 591169

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Chrisda to Main (#8323)

* Update attack-surface-reduction-rules-reference.md

Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'

* Update attack-surface-reduction-rules-overview.md

Consistency updates

* ASR rules report screenshot updates

More data

* Remove A3 from E3 gets MDO P1 refs

Per request

* Added Teams to report suspicious

* Update outbound-spam-high-risk-delivery-pool-about.md

Content VSO 591495

* [AIRA] Bot Remediation - dansimp (defender-docs-pr, d365-test8b-dansimp) (#8085)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update email-analysis-investigations.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - deniseb (defender-docs-pr, d365-test8b-deniseb) (#8086)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update authorship information in documentation

* Change section title to 'Related content'

Updated section title and added related content links.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Denise Vangel-MSFT <deniseb@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [1/2] (#8087)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Fix formatting in air-report-false-positives-negatives.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-e) [2/2] (#8090)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - unowned (defender-docs-pr, em-test8d) (#8091)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* fix(COPY-EDIT): editorial (#8089)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* CFA article updates (#8149)

* Configure controlled folder access

* Added Windows Security app procedures

And removed them elsewhere

* CFA overview article rename

* CFA

* CFA Overview

* Delete customize-controlled-folders.md

* Removed CFA article from MDB

And also cleaned up ASR/ASR rule references and links, including any Intune procedure links.

* Link and link title updates for CFA

* Update address-unwanted-behaviors-mde.md

* New monitor CFA article

Remnants of the old evaluate CFA article + Windows event viewer steps/info from the CFA overview article.

* Copy and Technical edits

* CFA demonstrations

* CFA demos

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* CFA/ASR demo updates

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* Final edits

* Offending file name renames

Per build report

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-c) (#8082)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update address-compromised-users-quickly.md

* Fix formatting of ms.custom metadata in markdown

* Fix formatting of custom metadata in markdown file

* Correct 'ms.custom' formatting in documentation

Fixed formatting of the 'ms.custom' metadata entry.

* Update custom metadata in mdo-portal-permissions.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8053)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* docs(sentinel): add parameterized notebook job guidance

Add steps for defining notebook parameters, refreshing job parameters, and overriding values when running a notebook job manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 11) - NEW SERIES, IGNORE BATCH NUMBER (#7939)

* Docs: soft rebrand Defender XDR to Defender (batch 11)

Replace 'Defender XDR' and 'Microsoft Defender XDR' with 'Defender' and
'Microsoft Defender' in body text of 20 advanced hunting schema and
feature articles, per Microsoft Defender branding guidelines.

Preserved unchanged:
- appliesto metadata fields
- [!INCLUDE references
- ms.service and other metadata fields
- Link display text referencing external page titles
- URL paths and fragments

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back change.

Updated description to specify Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-2) (#8016)

* Docs: soft rebrand Defender XDR → Defender (batch 612-2)

Update 18 advanced hunting files to replace 'Defender XDR' and
'Microsoft Defender XDR' with 'Defender' and 'Microsoft Defender'
in body text per branding guidelines. Protected references
(metadata, includes, API names, historical records, plugin names)
are left unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

* Roll back change.

* Roll back change.

Updated the description to include 'XDR' in the title.

* Roll back change.

* Roll back changes.

Updated references to Microsoft Defender XDR in the document.

* Roll back changes.

Updated references from Microsoft Defender for Endpoint to Microsoft Defender XDR in the migration guide.

* Roll back changes.

* Roll back changes.

Updated title and references to reflect Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-9) (#8030)

* Docs: soft rebrand Defender XDR → Defender (batch 612-9)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 10 files. 1 file had no eligible changes (all XDR refs were protected product names).

Protected references preserved: metadata fields, [!INCLUDE] lines, image alt text, historical changelog entries in whats-new.md, API endpoint names, external blog post titles, 'Defender Experts for XDR' product name, XDR capability descriptions (XDR solution, XDR tools, XDR/SIEM).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR, including changes to titles and descriptions throughout the content.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix typo in Microsoft Defender XDR description

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Fix directory path and update checksum commands (#8334)

Command errors caused by folder structure or incorrect quotation/space within a zip file.

* Clarify prerequisites for attack disruption exclusions based on Unified RBAC state (#8276)

Split the Prerequisites section into Device and Identity exclusion
permissions, showing the required roles when Unified RBAC is enabled
versus disabled. Cross-link to Unified RBAC activation and custom
permissions docs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#8341)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update value-data-connectors.md with onboarding notes (#8254)

* Update value-data-connectors.md with onboarding notes

Added note about device onboarding requirements and limitations.

* Apply suggestion from @DebLanger

* Update date and permissions in get-machines.md (#8344)

Updated the date and permissions section in the API documentation.

* wi-589516: Remove '| Microsoft Docs' suffix from title metadata (#8255)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>

* Update email post delivery events documentation

* Learn Editor: Update fixed-reported-inaccuracies.md (#8308)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA (#8354)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA

* Updating what's new

* Removing preview note

* Docs: soft rebrand Defender XDR → Defender (batch 2) (#8191)

* Docs: soft rebrand Defender XDR → Defender (batch 2)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR'
with 'Defender' in eligible locations per branding guidelines.

Files updated:
- critical-asset-management.md (1 replacement)
- get-started-exposure-management.md (4 replacements)
- prerequisites.md (3 replacements)
- whats-new.md (0 - all references in historical What's New entries)

Preserved XDR references in:
- Bold UI navigation paths (prerequisites.md line 67)
- Historical What's New entries (whats-new.md lines 179, 310)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 13) (#7941)

* docs: soft rebrand Defender XDR → Defender (batch 13)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers (#8350)

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers

- Add limitation note to Security findings (Preview) component in AKS, EKS, and GKE tabs
  stating it cannot be enabled through Azure Policy and must be toggled in plan Settings
- Rename 'Security findings' to 'Security findings (Preview)' for accuracy
- Remove 'This article explains' from opening line per style guide

Addresses US585115 / IcM 662676555 / CxE WI 19929

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestions from code review

Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add identity assessment key mappings to transition reference article (#8351)

* Add identity assessment key mappings to transition reference article

Replace placeholder in Microsoft Defender for Identity section with
assessment key mapping table for 5 guest/disabled account assessments.
Uses 'assessment' terminology per Roy's guidance.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8050)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8048)

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentinel-mberdugo-02) (#8047)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title from 'Next steps' to 'Related content'

* Fix formatting of title in integration guide

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Cloud security reporting GA (#8267)

* Cloud security reporting GA: remove preview, add release note and card customization

- Remove (Preview) from title and H1 in cloud-security-reporting.md
- Remove preview features prerequisite
- Add card customization capability
- Add June 30 GA release note entry

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add customize cards section with screenshots to cloud reporting article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Clarify that card customization is only for cards labeled Customizable

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add migration guidance for Sentinel incident creation rules to Defender alert grouping (#7952)

* Add Sentinel-to-Defender alert grouping migration guidance

* Relocate Sentinel migration article to unified-secops docset

* Update migration images and include restored xdr article copy

* Remove duplicate defender-xdr migration article copy

* Update image alt text for incident correlation migration doc

* Fix validation issues for incident correlation migration docs

* Fix broken migration link and update image references

* israel review

* Fix PR validation issues for links, metadata, and image naming

* Fix broken unified secops migration links

* Remove image from incident creation migration article

* Remove unused onboarding image file

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Revert to correct cross-docset URL link for new migrate-sentinel article

* Revert to correct cross-docset URL link for new migrate-sentinel article

---------

Co-authored-by: Guy Wild <98332688+guywi-ms@users.noreply.github.com>

* Clarify DlpInfo description in deviceinfo table

Updated DlpInfo description to clarify its content and added a reference link for further information.

* GA multicloud recommendations June 30: release notes, score impact, new tag docs, reference updates (#8275)

* Docs: GA multicloud recommendations June 30 - score impact, new tag, ref updates

- Add June 30 GA release note for expanded multicloud coverage
  (~150 recommendations, ~90 resource types, score impact)
- Add GA/Preview rows to recommendations release notes
- Document 'New' tag (30-day window), change log, and portal banner
  in review-security-recommendations.md (both portal pivots)
- Add Secure Score impact callout to secure-score-security-controls.md
- Remove (Preview) from 217 multicloud recommendations across 6
  reference files (networking, data, identity-access, app-services,
  compute, container)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix: restore deleted category tabs and select step in review-security-recommendations.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix DlpInfo reference link in deviceinfo-table.md

Updated the reference link for DlpInfo properties to ensure it points to the correct documentation.

* Add event-driven response guide for Defender for Storage malware scanning (#8345)

- Expand Event Grid setup walkthrough in configure-malware-scan article with 3-step process
- Add 3 Azure Functions templates: quarantine, auto-delete, and alert/notification
- Add sample payloads for No threats found and Not Scanned result types
- Add event delivery troubleshooting section covering permissions, networking, and subscription validation
- Add Event-driven response feature bullet to introduction article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Align identity risk score GA heading with what's-new convention

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Widespread Local Admin predefined classification rules (#8289)

* Add Widespread Local Admin classification rules and release note

- Add three new Identity classification rules to predefined classifications:
  Widespread Local Admin on Servers (High), Widespread Local Admin on
  Workstations (High), and Widespread Local Admin on Servers and
  Workstations (Very High)
- Add June 2026 release note entry for the new Identity classifications

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Reorder Widespread Local Admin rules and add dependency note

- Reorder to: Servers, Workstations, Servers and Workstations in both files
- Add note to 'Servers and Workstations' rule indicating it relies on
  the Servers and Workstations classifications

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* wi-586653-USX-transition-docs-improvements-CxE (#8183)

* wi-586653-USX-transition-docs-improvements-CxE

Changes:
 Investigation row (line 50):

   - Added hyperlinks to "Attack story" and "incident graph" � /defender-xdr/investigate-incidents#attack-story
   - Added blast radius analysis mention with link � /defender-xdr/investigate-incidents#blast-radius-analysis
   - Removed "(Sentinel Graph)" label � the actual feature name is just "incident graph"

  Security Copilot row (line 58):

   - Added "autonomous Security Copilot agents" with link � /defender-xdr/security-copilot-agents-defender
   - Added "threat hunting" agent link � /defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent
   - Added "Included capacity for E5/E7 customers" with link � /copilot/security/security-copilot-inclusion
   - Updated Benefits column: "agentic defense" added

* mto - playbooks and lighthouse

 Changes in sentinel/move-to-defender.md:

   - Added IMPORTANT callout clarifying that MTO doesn't replace Azure Lighthouse (gap 10), listing operations that still require Lighthouse
   - Added note that playbooks can't be distributed through MTO content distribution, with CI/CD workaround (gap 11)

* Update move-to-defender.md

Changes in sentinel/move-to-defender.md:

 - Gap 13 (SCU inclusion): Added E5/E7 included Security Copilot capacity mention with link to the existing NOTE callout about transition costs
 - Gap 15 (Investigation visuals): Added paragraph about attack story, incident graph, and blast radius analysis with links, under "Update incident triage processes"
 - Gap 8 (AAD/UEBA): Added note at end of UEBA section explaining that Sentinel UEBA signals feed into automatic attack disruption after transition, with link
 - Gap 12 (SOC Optimization): Added new "Use SOC optimization recommendations" subsection explaining cross-service vs Sentinel-only differences, with links to docs and API

* fix build error

* added "prioritize containment actions"

* small tweaks

* corrections

* Update move-to-defender.md

* Alert trigger scope limitation updates

1. In create-manage-use-automation-rules.md, after the trigger table, a NOTE now says:

“In the Defender portal, alert triggers work only on Microsoft Sentinel alerts,” and links to Enhanced Alert Trigger (Public Preview).

2. Updated core automation rules limitation text to include the solution path:

In automate-incident-handling-with-automation-rules.md, the NOTE under alert-triggered automation now explicitly says Defender XDR alert-triggered automation isn’t available in the Defender portal and points to Enhanced Alert Trigger (Public Preview).

3. Standardized migration/transition include messaging so the limitation points to the preview workaround:

In automation-in-defender.md, the “Automation rules with alert triggers” row now includes the limitation plus a direct link to Enhanced Alert Trigger (Public Preview).

4. Made the destination feature explicitly labeled as preview:

In generate-playbook.md, the section heading was updated to “Enhanced alert trigger (Public Preview).”

* Bookmark deprecation

* 5–10 minute batching window

updated note in sentinel\automate-incident-handling-with-automation-rules.md

* data lake - regional data processing limitation

* mutli-tenant: Playbooks not distributable via MTM

* Multitenant operations (MTO) and Azure Lighthouse

* PR build errors + bookmarks- advanced hunting

* Adjusting spacing between tables

* Clarify bookmarks note

* Removed "Public" from "Public Preview"

* bookmarks update

* bookmarks tweak

* 5-10 min lag - formatting

* ueba update

* Update advanced-hunting-microsoft-defender.md

* Remove (Preview) from enhanced triggers

Confirmed with PM Guy Shmeltzer, enhanced triggers are already GA

* Move MTO vs Azure Lighthouse content to separate branch/PR (wi-592684)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move WIP content to part-2 branch; revert unresolved items to main

Removes still-in-progress content (AAD context, E5/E7 Copilot capacity, SOC
optimization subsection, regional workspace support, MTM playbook distribution)
from the publishing branch. Adaptations reverted to main; pure additions removed.
Approved content retained.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken link to migrate-sentinel-incident-creation-rules-alert-grouping

Correct the docset path from /unified-secops/ to /unified-secops-platform/ where
the target article actually resides.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken migrate-rules link in Defender-Sentinel integration article

Correct /unified-secops/ to /unified-secops-platform/ for the migrate article path.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* mshta recommendation - GA

* Add AI agent predefined classification rules (#8317)

- Add new AI agent category to predefined classifications
- Add Executive-Sponsored AI Agent rule (Medium criticality)
- Add AI Agent with Privileged Business System Write Access rule (Medium criticality)
- Add what's new entry for June 2026

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Eliminate redundant click-through procedures in Defender for Endpoint content (1 of 2) (#8339)

* Eliminate redundant click-through procedures in Defender for Endpoint content

* Fix bullets

* Add docs

* Add files

* Add files

* Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2) (#8359)

* Eliminate redundant click-through procedures in Defender for Endpoint content (2 of 2)

* Fix warning

* Update release-notes.md (#8365)

* Learn Editor: Update release-notes.md

* Learn Editor: Update release-notes.md

* Update support-matrix-defender-for-cloud.md (#8364)

* Learn Editor: Update support-matrix-defender-for-cloud.md

* Learn Editor: Update support-matrix-defender-for-cloud.md

* Update regional-availability.md (#8363)

* Learn Editor: Update regional-availability.md

* Learn Editor: Update regional-availability.md

* Add UAE North and UAE Central support for Defender for APIs and API security posture management in DCSPM (#8325)

* Add UAE North and UAE Central support for Defender for APIs and API security posture

Microsoft Defender for APIs and API security posture management in Defender CSPM now support the UAE North and UAE Central Azure regions. Update region lists and add a release note for the June 29, 2026 release.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 23) (#7959)

* docs: soft rebrand Defender XDR → Defender (batch 23)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 18) (#7954)

* docs: soft rebrand Defender XDR → Defender (batch 18)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: soft rebrand Defender XDR → Defender (batch 21) (#7957)

* docs: soft rebrand Defender XDR → Defender (batch 21)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Address build warning.

Added a section on required permissions for Defender for Identity in Microsoft Defender.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "[AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentine…" (#8373)

This reverts commit 7138bc781bf3c32c0099bd2c8b5d60ccaa4f1ab9.

* Revert "fix(COPY-EDIT): editorial (#8048)" (#8374)

This reverts commit b7e81b8cbc50a5adb4b767a180ec86ce16857156.

* Revert "fix(COPY-EDIT): editorial (#8050)" (#8375)

This reverts commit d054038bbad2c30c31aa5a112a18cdfffd9f9f1f.

* Add Simple Flows automation rules article (AB#570290) (#7690)

* Update Simple Flows action references table and TOC

* Fix broken bookmark in permissions link

The target article doesn't have a #permissions-for-automation-rules anchor.
Drop the anchor and link to the article generally.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Dissolve Known limitations section into action context

Move each limitation next to the action it constrains:
- Email-wide constraints (fixed template, fixed sender, no CC/BCC, no audit log) consolidated into a single NOTE callout after the Actions reference table.
- Assign SLA Policy: existing-policy caveat appended to the action's Behavior cell.
- 10-tasks-per-rule limit was already documented in the Add Task row, so the duplicate bullet is dropped.

Also align Update Case field labels with the feature spec (Email recipients, Grace period).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Cross-link Simple Flows from existing automation-rules articles

Add NOTE callouts pointing to the new Simple Flows article from:
- automate-incident-handling-with-automation-rules.md (Triggers + Actions sections)
- create-manage-use-automation-rules.md (Choose your trigger + Add actions sections)

Each callout is gated on Defender-portal onboarding to match the new feature's availability.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.githu…
Shawn Kupfer (ShawnKupfer) added a commit that referenced this pull request Sep 4, 2026
* Fix issues noted in AI remediation work (9 of 10) (#9105)

* Fix issues noted in AI remediation work (9 of 10)

* Fix errors

* Restore original documentation formatting

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: c22decca-6bd3-48ab-b340-3ac7ecc42866

* Restore remaining original formatting

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: c22decca-6bd3-48ab-b340-3ac7ecc42866

* Restore underline markup

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: c22decca-6bd3-48ab-b340-3ac7ecc42866

* Update detect-and-remediate-outlook-rules-forms-attack.md

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Copilot-Session: c22decca-6bd3-48ab-b340-3ac7ecc42866

* [mac] What's new for 101.26062.0012 (#9111)

* [mac] What's new for 101.26062.0009

* [mac] What's new for 101.26062.0011

* Add macOS AI discovery release note

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a576e3ad-0fec-474f-9f6c-516dfdec8789

* [mac] whatsnew 101.26062.0012

---------

Co-authored-by: j0shbregman <joshbregman@microsoft.com>
Copilot-Session: a576e3ad-0fec-474f-9f6c-516dfdec8789

* Update README (#9113)

Per public PR https://github.com/MicrosoftDocs/defender-docs/pull/581

* First seen at field behavior

* tamper protection audit mode public preview documentation (#9116)

* tamper protection audit mode public preview documentation

* added images

* removed appendix content

* fixed images

* fixing

* fixing

* adding two more images

* fixing images

* final edit

* preview tag

* what's new entries

* final edits

* fix bash

* fix command it test a tampering scen

* fixing link in whats new

* fixing link in whats new

* tabs in releases page

* edited linux preference page

* fixed audit mode version

* release notes

* fixing syntax

* removed release notes pivot changes

* fix

* updated Defender for Endpoint release notes

* Revert "tamper protection audit mode public preview documentation (#9116)" (#9123)

This reverts commit a617229a447f8a905689b3296142569f383abdcc.

* Update Protection & posture insights report details (#9124)

Feature is GA - removed note about report being in Preview with limited availability.

@chrisda for review.

* Update attack-simulation-training-simulation-automations.md (#9125)

Updates per email request

* First Contact Safety Tip clarification (#9127)

* Update attack-simulation-training-simulation-automations.md

Updates per email request

* Update anti-phishing-policies-about.md

First Contact Safety Tip clarification per email request

* Defender catch-up scan updates- #20678 (#9128)

* Defender catch-up scan updates- #20678

Per <https://github.com/MicrosoftDocs/defender-docs/issues/537>

* Clarify Defender catch-up scan behavior

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add CVE details ARG schema release note

* Clarify CVE details ARG data consumption update

* Clarify CVE details ARG update already happened

* Remove retirement clarification sentence

* Update Logstash DCR article for output plugin v2.5.0

- Bump plugin to v2.5.0 and update RubyGems links
- Add Logstash 9.3.3 and 9.4.0; add security-update links for affected versions
- Rename config params: client_id, client_secret, dcr_id, stream_name
- Rewrite managed identity section around DefaultAzureCredential; remove invalid managed_identity/managed_identity_object_id
- Replace optional configuration table and add changelog entries through 2.5.0
- Update known issues to reference new waiting-time variables

* More catch-up scan updates (#9132)

* Defender catch-up scan updates- #20678

Per <https://github.com/MicrosoftDocs/defender-docs/issues/537>

* Clarify Defender catch-up scan behavior

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* More catchup scan updates

From: https://github.com/MicrosoftDocs/defender-docs/issues/537. Also did copy/technical/consistency edits on schedule-antivirus-scans-intune and use-intune-config-manager-microsoft-defender-antivirus

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update release-notes.md

* Learn Editor: Update release-notes.md

* Updated First seen at field description

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Remove password protection preview labels

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 28174cd6-9878-4f1c-97f8-6dfc88d22241

* Updated CVE details tenant scope guidance

* Update email-authentication-dkim-configure.md (#9145)

* Update email-authentication-dkim-configure.md

correction

* Update email-authentication-dkim-configure.md

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Document automatic auditing for non-DC identity servers (#9136)

* Document automatic auditing for non-DC servers

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 55a93760-c6f7-43b7-8938-dade4d7461a6

* Update whats-new.md

---------

Copilot-Session: 55a93760-c6f7-43b7-8938-dade4d7461a6

* reapplied tamper protection audit mode public preview documentation

* Update outbound-spam-restore-restricted-users.md (#9153)

Updates per email request.

* updated agentless machine scanning guidance (#9151)

* updated agentless machine scanning guidance

* updated agentless scanning section links

* Fix issues noted in AI remediation work (10 of 10) (#9154)

* Fix issues noted in AI remediation work (10 of 10)

* Restore Office 365 article formatting

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update configure-junk-email-settings-on-exo-mailboxes.md

* Fix formatting of Set-MailboxJunkEmailConfiguration cmdlet

Updated formatting for cmdlet name in the Junk Email settings documentation.

* Improve cmdlet formatting in connection filter policy doc

Updated formatting for cmdlet name in PowerShell section.

* Refine email clustering analysis description

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update advanced-hunting-devicelogonevents-table (#9155)

* Update outbound-spam-restore-restricted-users.md

Updates per email request.

* Update advanced-hunting-devicelogonevents-table.md

Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/8701

* Update sentinel-siem-application-card.md (#9156)

Updates per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9000

* Nested API support (#9157)

Per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9001

* Retirement of contanerized SAP agent (#9158)

Per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9043

* .aspx link fixes (#9161)

* Retirement of contanerized SAP agent

Per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9043

* .aspx link fixes

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* update transition recs page (#9165)

* update transition recs page

* removed note from review page

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update ai-model-security.md

* Add Remote tenant group (GDAP) option to URBAC custom role assignment

Documents the new Remote tenant group option in the Add assignment side pane, enabling GDAP-based cross-tenant URBAC assignment. Target go-live: 2026-08-31. Resubmission of public PR MicrosoftDocs/defender-docs#579 per @v-regandowner's guidance.

* removed tamper protection page

* removing release note

* Update accounts.md (#9169)

* Learn Editor: Update accounts.md

* Learn Editor: Update accounts.md

* Update deprecation notice for data risk graph

* Platform fixes from SME review (#8852)

* Platform fixes from SME review

* Fix warnings

* Update anti-spam-bulk-complaint-level-bcl-about.md (#9171)

* Update anti-spam-bulk-complaint-level-bcl-about.md

* Update anti-spam-bulk-complaint-level-bcl-about.md

* Link updates/fixes (#9175)

* Update anti-spam-bulk-complaint-level-bcl-about.md

* Update anti-spam-bulk-complaint-level-bcl-about.md

* Update release-notes-mde-archive.md

Formatting and link fixes

* Link updates

* Build report fixes

* Article alignment (#9176)

Intune procedures standardization and copy/technical edits.

* Update date and improve clarity in overview

Updated the date for the Codename MDASH overview and refined the wording in the 'Prepare' section for clarity.

* Add CallActivityEvents advanced hunting schema reference (#8949)

* Add CallActivityEvents hunting schema reference

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2879d2fb-b4ab-490b-96cb-e11e4735efe6

* Address CallActivityEvents review feedback

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @Stacyrch140

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Stacy Chambers <102548089+Stacyrch140@users.noreply.github.com>
Copilot-Session: 2879d2fb-b4ab-490b-96cb-e11e4735efe6

* Update ms.date and remove deletion note (#9178)

Bump ms.date to 07/01/2026 and remove the sentence claiming that existing Teams meetings, chats, channels, and calls are deleted after adding a block entry. This clarifies the Tenant Allow/Block List guidance in defender-office-365/tenant-allow-block-list-teams-domains-configure.md.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 91c4341f-a0c5-4d2a-9caf-7a91f19f5ba8

* Clarify Teams mailbox requirements for user reporting (#9179)

* Clarify Teams mailbox requirements

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0008fc20-c9b1-4711-96d3-3c2ea1cc6dd2

* Clarify reporting mailbox restrictions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0008fc20-c9b1-4711-96d3-3c2ea1cc6dd2

---------

Copilot-Session: 0008fc20-c9b1-4711-96d3-3c2ea1cc6dd2

* Update android-configure (#9188)

Consolidated redundant Intune procedures, copy edit and technical edit.

* Remove line break tag (#9190)

* Chrisda to Main (#9191)

* Update android-configure

Consolidated redundant Intune procedures, copy edit and technical edit.

* Update android-configure.md

* Intune policy standardization

* Update configure-cloud-block-timeout-period-microsoft-defender-antivirus.md

Intune policy standardization, Defender portal policy standardization, and added missing PowerShell procedure.

* Revert "Add Remote tenant group (GDAP) option to URBAC custom role assignment"

* Learn Editor: Update mdash-foundry-integration.md

* Update alerts-mdi-classic.md (#9197)

* Learn Editor: Update alerts-mdi-classic.md

* Learn Editor: Update alerts-mdi-classic.md

* Update alerts-xdr.md (#8902)

* Learn Editor: Update alerts-xdr.md

* Learn Editor: Update alerts-xdr.md

* Learn Editor: Update fixed-reported-inaccuracies.md (#9185)

* Document the DLP to Purview migration tool and non-Microsoft app support (#9203)

Add a section covering the DLP to Purview migration tool: prerequisites,
supported scope, the four wizard steps, post-migration review in Purview,
FAQ, known issues, and wizard screenshots.

Add a Non-Microsoft app support section listing the SaaS apps Purview DLP
supports (Box, Dropbox, Google Workspace, Salesforce) with prerequisites
and a pointer to the Purview documentation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add known limitation for Teams launched from proxied Google Workspace sessions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update advanced-hunting-datasecuritybehaviors-table.md

* Learn Editor: Update advanced-hunting-datasecuritybehaviors-table.md

* Learn Editor: Update defender-sensor-change-log.md

* Learn Editor: Update defender-sensor-change-log.md

* Learn Editor: Update ai-code-security-onboarding.md

* Learn Editor: Update mdash-foundry-integration.md

* Learn Editor: Update mdash-foundry-integration.md

* Learn Editor: Update mdash-foundry-integration.md

* Learn Editor: Update ai-code-security-onboarding.md

* Learn Editor: Update ai-code-security-onboarding.md

* Learn Editor: Update whats-new.md

* Learn Editor: Update whats-new.md

* Learn Editor: Update ai-code-security-onboarding.md

* Learn Editor: Update whats-new.md

* Learn Editor: Update mdash-foundry-integration.md

* Add Remote tenant group (GDAP) option to URBAC custom role assignment

Documents the Remote tenant group option in the Add assignment side pane, enabling GDAP-based cross-tenant URBAC assignment. Feature is live for customers today (2026-08-31) per Eng green light. Resubmission after revert PR #9195.

* Update remediate-vulnerability-findings-vm.md (#9205)

* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Updated published docs with latest contributions (#8824)

* Update identity remediation actions for unified multi-connector support

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Make identity actions section generic and reference remediation actions page

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Use comma-separated values for supported identity sources column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Update roles table with connector columns for identity providers and SaaS apps

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add MDA roles for SaaS apps column and SOC Identity Responder role

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Remove Deactivate and Set account risk actions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add Entra ID roles for Force password change action

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add SOC Identity Responder to Entra ID column for response actions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Reference required permissions page for identity provider column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add SOC Identity Responder to Defender for Identity response actions permissions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Clarify identity actions span connectors across on-prem, Entra ID, IAM, and SaaS

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Trim identity actions view details to account settings only

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Fix Supported actions table: remove stray SOC role and link column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Remove SOC Identity Responder from Enable action (not supported)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Learn Editor: Update alerts-containers.md

* Learn Editor: Update alerts-containers.md

* Remove AI Agent write access classification

Removed the description for AI agents with privileged business system write access from the predefined classifications section.

* Learn Editor: Update ai-threat-protection.md

* Move account correlation rules under Settings (#8793)

* Move account correlation rules under settings

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Adjust account correlation navigation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Use full account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Restore original account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Resize account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

---------

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

---------

Co-authored-by: izauer-bit <76057672+izauer-bit@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: EyalGur74 <160857568+EyalGur74@users.noreply.github.com>
Co-authored-by: Sapir Schneider <296893019+SapirSchneiderService@users.noreply.github.com>
Co-authored-by: Liran Levy <309411196+liran-levy3@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* OOB publish for sync PR (#8976)

* Docs: soft rebrand Defender XDR → Defender (batch 612-6) (#8027)

* Docs: soft rebrand Defender XDR → Defender (batch 612-6)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 20 files. Protected references (metadata, includes, UI navigation, image alt text, detection source names, acronym definitions, XDR detection engine names) are preserved.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back Changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix conflict.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/defender-docs (branch public) (#7591)

* Add custom graph cost management link in graph charges section

* Update mdb-faq.yml

Updating public documentation because numerous support cases have been opened due to documentation being unclear. Government customers are not included in this section and should be clarified for customers when trying to understand what licensing is required.

* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#525)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Ofer Schreiber <ofer@bigpanda.io>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update advanced-hunting-emailattachmentinfo-table.md (#307)

Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. `.exe`) while the field is actually a file content type (e.g. `txt;text` or `email;mime` or `png`).

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update advanced-hunting-take-action.md with query reference (#406)

* Update advanced-hunting-take-action.md with query reference

Added Kusto query reference for enabling 'Submit to Microsoft' and 'Initiate automated investigation'. To make it more clear after it was raised in the community

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Update manage-event-based-updates-microsoft-defender-antivirus.md (#345)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update with the correct GPO setting name (#365)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* MDB: Update references to the onboarding (#377)

* fix: MDB, update onboarding, rename MAM to WIP

Azure Portal has slowly but progressively been moved to Entra admin center: Update the URL and the actual naming in the portal.

MAM isn't mentioned it seems to be replaced by Windows Information Protection in the same screen.

* fix: Further replace MAM occurrences by WIP 

MAM wording has been removed from both the old Azure portal, as well as in Entra admin center.

* fix: MDB, add updated screenshot MDM and WIP user scopes

While the structure is mostly unchanged, add new screenshot that includes current namings and same design of selector / radio buttons.

* MDB: Include updated screenshot

Include updated screenshot and update description of the picture.

* MDB: Delete old screenshot of MEM/MAM user scope settings

New picture was added with new name, this one is now obsolete.

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Change MDEConfig.txt to DefenderDTconfig.txt (#418)

"DefenderDT.exe -makeconfig" crates a file named DefenderDTconfig.txt instead of MDEConfig.txt

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Update configure-network-connections-microsoft-defender-antivirus.md (#448)

Fixing broken link for https://learn.microsoft.com/en-us/windows/privacy/manage-windows-1709-endpoints#windows-update

No longer works because of ham-fisted MS redirects.

* Update advanced-hunting-microsoft-defender.md (#343)

Add to "known Issues":
When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting.

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Fix grammar in Teams block entry instructions (#496)

* Fix grammar in Teams block entry instructions

Blocking a domain does not block the Teams meeting invitation itself. Blocking a domain will remove the user from the Teams meeting chat after the meeting ends. The current documentation (Teams Meetings) may be misleading as to suggest that it affects all meetings.

* Fix grammar in Teams block entry instructions

Corrected grammatical errors in the block entry explanation.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Clarify instructions for running Client Analyzer shipped version  (#498)

* Clarify instructions for running Client Analyzer shipped version in live response

Adjust the format which is clearer for binary version and python version separately.

* Update run-analyzer-linux.md

* Fix formatting and wording in run-analyzer-linux.md

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Update faqs-on-tamper-protection.yml (#532)

Remove bracket so link properly connects to target URL

* Update quarantine-shared-mailbox-messages.md (#528)

* Update quarantine-shared-mailbox-messages.md

Updated wording for clarity and expanded scope to include both shared and user mailboxes.

* Update quarantine management instructions and date

Updated the date for the document and refined the instructions for accessing quarantined messages in shared mailboxes.

* Update shared mailbox quarantine management instructions

Clarified that automapping is no longer required for managing quarantined messages in shared mailboxes. Updated conditions for accessing quarantined messages.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Resolve syncing conflicts from repo_sync_working_branch to public (#529)

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-04) (#8059)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix fictional bookmarks AIRA created

Removed redundant options for enabling UEBA and streamlined the text.

* Remove bookmark to nonexistent content

Removed redundant sentence in the UEBA documentation.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update release-notes-recommendations-alerts.md

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [2/2] (#8088)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix metadata for PIM in MDO configuration document

* Fix metadata for safe attachments configuration doc

* Update ms.custom metadata in documentation

* Fix formatting in submissions admin review document

* Fix formatting for ms.custom in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-06) (#8061)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix bad AIRA edit

Updated section header from 'Next steps' to 'Next step'.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b5) (#8096)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting of ms.custom metadata in document

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8060)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8062)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8072)

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8095)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Clarify that the Risky IP address category is dynamic (#8198)

* Clarify that the Risky IP category is dynamic and can expire

Add a note explaining that the Risky category is assigned automatically
based on threat intelligence and is removed if no further malicious
activity is detected. All other categories are assigned manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: AbbyMSFT <88824859+AbbyMSFT@users.noreply.github.com>

* Apply suggestion from @AbbyMSFT

* Apply suggestion from @AbbyMSFT

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* new onboarding (#7970)

* new onboarding

* updates

* updates

---------

Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-usp-test8a-mberdugo) (#8077)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Remove AIRA-duplicated ai-usage metadata

Removed 'ai-usage' line from the document header.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Update approval functionality (#8303)

* Update approval functionality (#8304)

* docs(sentinel): add parameterized notebook jobs

Adds overview and detailed guidance for parameterized notebook jobs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* WI591424: GA transition for serverless containers docs

* Restore historical preview note and keep separate GA release note

* Move June 25 GA note to top of table and section list

* Document Registry access requirement for full Serverless Containers features

* Update defender-for-cloud/release-notes.md

* Update defender-for-cloud/release-notes.md

* Mark Serverless Containers as supported in Defender portal

* Move serverless containers GA date to July 1

* Place July 1 release note under July table

* Set July 1 ms.date across remaining PR pages

* Version 26.1.1 (#8316)

* Version 26.1.1

* Fixes

* Mapping updates to transition from grouped to individual recommendations (#8151)

* Transition from grouped to individual recommendations

* Update transition article with end-state classification for deprecated assessments

- Add explanation of 3 end-states (dynamic substitute, static substitute, no substitute)
- Add End-state and New assessment ID columns to all reference tables
- Change 'NA (Static)' to 'Unknown' in Category column for static substitutes (EDR, SQL)
- Mark EDR and SQL rows as static substitutes with [TBD] new assessment IDs
- Fix HostMisconfiguration → HostMisconfigurations per category list
- Mark GitHub security posture management row as [TBD] pending DevOps partner input
- Add placeholder section for Microsoft Defender for Identity (pending partner review)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date and clarify static substitute guidance

- Add July 31, 2026 as the grouped recommendation deprecation date
- Clarify that static substitute recommendations use 'Unknown' category
  and users should filter by assessment ID, not category filter

Per meeting with Roy Hirsch (June 21, 2026)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "Add July 31 deprecation date and clarify static substitute guidance"

This reverts commit c4f487921093d967d968310ed5e2773e07cf3291.

* Update grouped-to-individual recommendations article per Roy Hirsch review

- Remove IcM routing column from all tables (internal-only, not customer-facing)
- Fix ARG query field: securityCategories -> recommendationCategory
- Fix category name: 'Vulnerabilities' -> 'SoftwareUpdate' recommendation category
- Replace 'assessment key/ID' with 'recommendation ID' throughout
- Replace 'grouped assessment' with 'grouped recommendation' throughout
- Remove 'No substitute' end-state (deprecated items not included in this guide)
- Split each product table into Dynamic substitutes and Static substitutes sections
- Simplify table columns: Dynamic (Recommendation | Recommendation ID | Category),
  Static (Recommendation | Recommendation ID | New recommendation ID)
- Remove IcM routing reference from intro tip and reference section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename 'Recommendation category reference' to 'Recommendation transition reference'

Section now covers both dynamic (category-based) and static (recommendation ID-based)
transitions, so 'category reference' was no longer accurate.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date to transition guides

- Add July 31, 2026 deprecation date in transition-grouped-individual-recommendations.md
  (overview callout, adopting section, what you should do now callout)
- Add July 31, 2026 deprecation date in transition-disable-rules-exemptions.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update transition guide with Roy's final feedback

- SQL databases/servers recs: mark as deprecated, replace static substitute table with note and link to full SQL recommendations reference
- Containers: add Azure (c609cf0f) and AWS (682b2595) running container images as dynamic substitutes mapped to SoftwareUpdate
- GitHub security posture mgmt (fd104c01): update [TBD] with link to full DevOps recommendations reference
- Linux secure boot rec (ad50b498): not added (status unknown per Roy)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix SQL recommendations link to point to VA rules mapping article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Replace internal substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply manual edits and re-apply terminology changes

- Remove Secure Score row from comparison table
- Update vulnerability management example description
- Rename old query label and add note before new query
- Remove Secure Score during transition section
- Change EDR recs to deprecated recommendations
- Replace Dynamic/Static substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix terminology: replace 'Dynamic substitutes' with 'Replaced by individual recommendations' in Containers and DevOps sections; fix garbled text and table in Servers deprecated section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix files moved in error (#8310)

* fix files moved in error

* fixes

* [AIRA] Bot Remediation - AbbyMSFT (defender-docs-pr, 20260615-dfi-root-b-r1) (#8073)

* fix(COPY-EDIT): batch

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b3) (#8094)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix ms.custom field formatting in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8074)

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Restructure MDA TOC around customer journey (#7505)

* Restructure MDA TOC around customer journey

Reorganize from feature-based sections to a lifecycle flow:
Deploy > Connect and discover > Assess risk > Control and protect >
Detect threats > Investigate and respond > Stream to SIEM > Manage

Key changes:
- Dissolve app governance silo into relevant phases
- Merge 'View and manage applications' into discovery
- Merge 'Information protection' into 'Control access and protect data'
- Move AI agent protection into discovery section
- Rename SIEM section to clarify outbound direction
- Move operations guide into 'Manage and configure'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename section to 'Investigate and respond to threats'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add PR target instruction to copilot-instructions.md

Ensure PRs are always created against MicrosoftDocs/defender-docs-pr
rather than the fork.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move app governance setup articles to appropriate sections

- 'Turn on app governance' moves into Configuration (it's a config task)
- 'Get started with app governance' moves into 'Discover and manage
  OAuth apps' (it's a product walkthrough, not deployment)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply content audit: move articles to correct lifecycle phases

Based on full-content audit of 35 cross-cutting articles:

Moved to 'Control access and protect data':
- manage-app-permissions.md (renamed to 'Manage OAuth app permissions')
- app-governance-visibility-insights-sensitive-content.md
- governance-discovery.md
- mde-govern.md
- ai-agent-protection.md and real-time-agent-protection (AI agent protection)

Moved to 'Investigate and respond to threats':
- app-governance-anomaly-detection-alerts.md
- app-governance-investigate-predefined-policies.md
- tutorial-flow.md (response automation, not SIEM)

Kept ai-agent-inventory.md in discovery (primary entry point).
AI agent discovery stays in Connect and discover; protection moves
to Control access.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename discovery sections for clarity

- 'Discover cloud apps (shadow IT)' -> 'Discover cloud apps and shadow IT'
- 'Discover and manage OAuth apps' -> 'Discover and manage OAuth apps with app governance'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Restructure MDA TOC: split discover/connect, rename access section

- Split 'Connect and discover apps' into separate 'Discover apps' and
  'Connect apps' sections, with discovery first
- Rename 'Control access and protect data' to 'Manage access and app behavior'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Consolidate app governance articles and clarify OAuth app scope in titles

- Flatten Connect apps TOC node (remove unnecessary intermediate level)
- Consolidate app governance articles:
  - Merge policies overview + get-started + predefined into single overview
  - Merge policies create + manage into single create-and-manage article
  - Merge threat detection overview + get-started + monitor into single article
  - Merge visibility insights overview + get-started into single article
- Update all app governance TOC nodes and article titles to include 'OAuth'
  to distinguish from SaaS app content
- Add redirects for 6 deleted articles
- Fix all internal links to deleted articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken links in index.yml to deleted articles

Update references to consolidated app governance articles that were
deleted upstream.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Resolve PR review blocking issues: typos, casing, and alt-text fixes

- Fix 'polcies' typo in alt-text (app-policies-overview)
- Add graphic-type prefix to two image alt-texts (app-policies-overview)
- Lowercase 'app governance' in alt-text (detect-remediate-overview)
- Remove duplicate 'the' (secure-apps-access-non-graph-api)
- Lowercase three 'app governance' instances (anomaly-detection-alerts)
- Title case 'Zero Trust' (index.yml)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8075)

Remediation for COPY-EDIT.
Files affected: 6

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-usp-test8a-guywi) (#8076)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title and content in mto-requirements.md

Renamed 'Next steps' section to 'Related content' and updated its content.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8078)

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-b) (#8081)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Improve formatting of simulation automation steps

Formatted the configuration steps into a bulleted list for better readability.

* Update attack-simulation-training-training-campaigns.md

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Update ms.custom metadata in connectors-remove-blocked.md

* Refactor ms.custom metadata in documentation

Updated ms.custom metadata to include a list format.

* Update ms.custom formatting in documentation

* Update ms.custom format in preset-security-policies.md

* Update quarantine-admin-manage-messages-files.md

* Fix formatting of ms.custom property in markdown

* Update ms.custom metadata format in markdown file

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* WI590578-table-insights (#8265)

* WI590578-table-insights

* quality fixes

* additional work

* updated conceptual page

* page quality fixes

* Refine Table insights guidance and restore Data Lake terminology

* Update manage-table-tiers-retention.md

* fixes to instructions

* Update manage-table-tiers-retention.md

* quality fixes

* fix

* fix title

* small fixes

* small fixes

* fix based on Nikita's comment

actually I realized there is one more change when in Whats new section when you click on tables, you can see data sources in side drawer.

* fixing broken list

---------

Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-d) (#8083)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting for ms.custom in alert policies document

* Fix formatting for ms.custom in audit log document

* Fix formatting of ms.custom in documentation

* Fix formatting in connection filter policies document

* Fix formatting in connectors-detect-respond-to-compromise.md

* Remove section for new Microsoft 365 administrators

Removed unnecessary section for new Microsoft 365 administrators and related content. There were no links or anything of value. It was essentially an ad, and even that ad didn't link to anything.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Document AI agent awareness for Entra ID service principals

- Add Used by AI agents (Preview) column to NHI details table
- Add Used by AI agents (Preview) stat to NHI insight cards
- Add what's-new entry for AI agent visibility

Work item: 591169

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Chrisda to Main (#8323)

* Update attack-surface-reduction-rules-reference.md

Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'

* Update attack-surface-reduction-rules-overview.md

Consistency updates

* ASR rules report screenshot updates

More data

* Remove A3 from E3 gets MDO P1 refs

Per request

* Added Teams to report suspicious

* Update outbound-spam-high-risk-delivery-pool-about.md

Content VSO 591495

* [AIRA] Bot Remediation - dansimp (defender-docs-pr, d365-test8b-dansimp) (#8085)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update email-analysis-investigations.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - deniseb (defender-docs-pr, d365-test8b-deniseb) (#8086)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update authorship information in documentation

* Change section title to 'Related content'

Updated section title and added related content links.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Denise Vangel-MSFT <deniseb@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [1/2] (#8087)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Fix formatting in air-report-false-positives-negatives.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-e) [2/2] (#8090)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - unowned (defender-docs-pr, em-test8d) (#8091)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* fix(COPY-EDIT): editorial (#8089)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* CFA article updates (#8149)

* Configure controlled folder access

* Added Windows Security app procedures

And removed them elsewhere

* CFA overview article rename

* CFA

* CFA Overview

* Delete customize-controlled-folders.md

* Removed CFA article from MDB

And also cleaned up ASR/ASR rule references and links, including any Intune procedure links.

* Link and link title updates for CFA

* Update address-unwanted-behaviors-mde.md

* New monitor CFA article

Remnants of the old evaluate CFA article + Windows event viewer steps/info from the CFA overview article.

* Copy and Technical edits

* CFA demonstrations

* CFA demos

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* CFA/ASR demo updates

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* Final edits

* Offending file name renames

Per build report

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-c) (#8082)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update address-compromised-users-quickly.md

* Fix formatting of ms.custom metadata in markdown

* Fix formatting of custom metadata in markdown file

* Correct 'ms.custom' formatting in documentation

Fixed formatting of the 'ms.custom' metadata entry.

* Update custom metadata in mdo-portal-permissions.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8053)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* docs(sentinel): add parameterized notebook job guidance

Add steps for defining notebook parameters, refreshing job parameters, and overriding values when running a notebook job manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 11) - NEW SERIES, IGNORE BATCH NUMBER (#7939)

* Docs: soft rebrand Defender XDR to Defender (batch 11)

Replace 'Defender XDR' and 'Microsoft Defender XDR' with 'Defender' and
'Microsoft Defender' in body text of 20 advanced hunting schema and
feature articles, per Microsoft Defender branding guidelines.

Preserved unchanged:
- appliesto metadata fields
- [!INCLUDE references
- ms.service and other metadata fields
- Link display text referencing external page titles
- URL paths and fragments

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back change.

Updated description to specify Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-2) (#8016)

* Docs: soft rebrand Defender XDR → Defender (batch 612-2)

Update 18 advanced hunting files to replace 'Defender XDR' and
'Microsoft Defender XDR' with 'Defender' and 'Microsoft Defender'
in body text per branding guidelines. Protected references
(metadata, includes, API names, historical records, plugin names)
are left unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

* Roll back change.

* Roll back change.

Updated the description to include 'XDR' in the title.

* Roll back change.

* Roll back changes.

Updated references to Microsoft Defender XDR in the document.

* Roll back changes.

Updated references from Microsoft Defender for Endpoint to Microsoft Defender XDR in the migration guide.

* Roll back changes.

* Roll back changes.

Updated title and references to reflect Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-9) (#8030)

* Docs: soft rebrand Defender XDR → Defender (batch 612-9)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 10 files. 1 file had no eligible changes (all XDR refs were protected product names).

Protected references preserved: metadata fields, [!INCLUDE] lines, image alt text, historical changelog entries in whats-new.md, API endpoint names, external blog post titles, 'Defender Experts for XDR' product name, XDR capability descriptions (XDR solution, XDR tools, XDR/SIEM).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR, including changes to titles and descriptions throughout the content.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix typo in Microsoft Defender XDR description

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Fix directory path and update checksum commands (#8334)

Command errors caused by folder structure or incorrect quotation/space within a zip file.

* Clarify prerequisites for attack disruption exclusions based on Unified RBAC state (#8276)

Split the Prerequisites section into Device and Identity exclusion
permissions, showing the required roles when Unified RBAC is enabled
versus disabled. Cross-link to Unified RBAC activation and custom
permissions docs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#8341)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update value-data-connectors.md with onboarding notes (#8254)

* Update value-data-connectors.md with onboarding notes

Added note about device onboarding requirements and limitations.

* Apply suggestion from @DebLanger

* Update date and permissions in get-machines.md (#8344)

Updated the date and permissions section in the API documentation.

* wi-589516: Remove '| Microsoft Docs' suffix from title metadata (#8255)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>

* Update email post delivery events documentation

* Learn Editor: Update fixed-reported-inaccuracies.md (#8308)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA (#8354)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA

* Updating what's new

* Removing preview note

* Docs: soft rebrand Defender XDR → Defender (batch 2) (#8191)

* Docs: soft rebrand Defender XDR → Defender (batch 2)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR'
with 'Defender' in eligible locations per branding guidelines.

Files updated:
- critical-asset-management.md (1 replacement)
- get-started-exposure-management.md (4 replacements)
- prerequisites.md (3 replacements)
- whats-new.md (0 - all references in historical What's New entries)

Preserved XDR references in:
- Bold UI navigation paths (prerequisites.md line 67)
- Historical What's New entries (whats-new.md lines 179, 310)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 13) (#7941)

* docs: soft rebrand Defender XDR → Defender (batch 13)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers (#8350)

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers

- Add limitation note to Security findings (Preview) component in AKS, EKS, and GKE tabs
  stating it cannot be enabled through Azure Policy and must be toggled in plan Settings
- Rename 'Security findings' to 'Security findings (Preview)' for accuracy
- Remove 'This article explains' from opening line per style guide

Addresses US585115 / IcM 662676555 / CxE WI 19929

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestions from code review

Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add identity assessment key mappings to transition reference article (#8351)

* Add identity assessment key mappings to transition reference article

Replace placeholder in Microsoft Defender for Identity section with
assessment key mapping table for 5 guest/disabled account assessments.
Uses 'assessment' terminology per Roy's guidance.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8050)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8048)

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentinel-mberdugo-02) (#8047)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title from 'Next steps' to 'Related content'

* Fix formatting of title in integration guide

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Cloud security reporting GA (#8267)

* Cloud security reporting GA: remove preview, add release note and card customization

- Remove (Preview) from title and H1 in cloud-security-reporting.md
- Remove preview features prerequisite
- Add card customization capability
- Add June 30 GA release note entry

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add customize cards section with screenshots to cloud reporting article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Clarify that card customization is only for cards labeled Customizable

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add migration guidance for Sentinel incident creation rules to Defender alert grouping (#7952)

* Add Sentinel-to-Defender alert grouping migration guidance

* Relocate Sentinel migration article to unified-secops docset

* Update migration images and include restored xdr article copy

* Remove duplicate defender-xdr migration article copy

* Update image alt text for incident correlation migration doc

* Fix validation issues for incident correlation migration docs

* Fix broken migration link and update image references

* israel review

* Fix PR validation issues for links, metadata, and image naming

* Fix broken unified secops migration links

* Remove image from incident creation migration article

* Remove unused onboardin…
Shawn Kupfer (ShawnKupfer) added a commit that referenced this pull request Sep 8, 2026
* Clarify CVE details ARG data consumption update

* Clarify CVE details ARG update already happened

* Remove retirement clarification sentence

* Update Logstash DCR article for output plugin v2.5.0

- Bump plugin to v2.5.0 and update RubyGems links
- Add Logstash 9.3.3 and 9.4.0; add security-update links for affected versions
- Rename config params: client_id, client_secret, dcr_id, stream_name
- Rewrite managed identity section around DefaultAzureCredential; remove invalid managed_identity/managed_identity_object_id
- Replace optional configuration table and add changelog entries through 2.5.0
- Update known issues to reference new waiting-time variables

* More catch-up scan updates (#9132)

* Defender catch-up scan updates- #20678

Per <https://github.com/MicrosoftDocs/defender-docs/issues/537>

* Clarify Defender catch-up scan behavior

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* More catchup scan updates

From: https://github.com/MicrosoftDocs/defender-docs/issues/537. Also did copy/technical/consistency edits on schedule-antivirus-scans-intune and use-intune-config-manager-microsoft-defender-antivirus

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update release-notes.md

* Learn Editor: Update release-notes.md

* Updated First seen at field description

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Remove password protection preview labels

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 28174cd6-9878-4f1c-97f8-6dfc88d22241

* Updated CVE details tenant scope guidance

* Update email-authentication-dkim-configure.md (#9145)

* Update email-authentication-dkim-configure.md

correction

* Update email-authentication-dkim-configure.md

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Document automatic auditing for non-DC identity servers (#9136)

* Document automatic auditing for non-DC servers

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 55a93760-c6f7-43b7-8938-dade4d7461a6

* Update whats-new.md

---------

Copilot-Session: 55a93760-c6f7-43b7-8938-dade4d7461a6

* reapplied tamper protection audit mode public preview documentation

* Update outbound-spam-restore-restricted-users.md (#9153)

Updates per email request.

* updated agentless machine scanning guidance (#9151)

* updated agentless machine scanning guidance

* updated agentless scanning section links

* Fix issues noted in AI remediation work (10 of 10) (#9154)

* Fix issues noted in AI remediation work (10 of 10)

* Restore Office 365 article formatting

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update configure-junk-email-settings-on-exo-mailboxes.md

* Fix formatting of Set-MailboxJunkEmailConfiguration cmdlet

Updated formatting for cmdlet name in the Junk Email settings documentation.

* Improve cmdlet formatting in connection filter policy doc

Updated formatting for cmdlet name in PowerShell section.

* Refine email clustering analysis description

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update advanced-hunting-devicelogonevents-table (#9155)

* Update outbound-spam-restore-restricted-users.md

Updates per email request.

* Update advanced-hunting-devicelogonevents-table.md

Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/8701

* Update sentinel-siem-application-card.md (#9156)

Updates per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9000

* Nested API support (#9157)

Per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9001

* Retirement of contanerized SAP agent (#9158)

Per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9043

* .aspx link fixes (#9161)

* Retirement of contanerized SAP agent

Per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9043

* .aspx link fixes

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* update transition recs page (#9165)

* update transition recs page

* removed note from review page

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update microsoft-defender-endpoint-releases.md

* Learn Editor: Update ai-model-security.md

* Add Remote tenant group (GDAP) option to URBAC custom role assignment

Documents the new Remote tenant group option in the Add assignment side pane, enabling GDAP-based cross-tenant URBAC assignment. Target go-live: 2026-08-31. Resubmission of public PR MicrosoftDocs/defender-docs#579 per @v-regandowner's guidance.

* removed tamper protection page

* removing release note

* Update accounts.md (#9169)

* Learn Editor: Update accounts.md

* Learn Editor: Update accounts.md

* Update deprecation notice for data risk graph

* Platform fixes from SME review (#8852)

* Platform fixes from SME review

* Fix warnings

* Update anti-spam-bulk-complaint-level-bcl-about.md (#9171)

* Update anti-spam-bulk-complaint-level-bcl-about.md

* Update anti-spam-bulk-complaint-level-bcl-about.md

* Link updates/fixes (#9175)

* Update anti-spam-bulk-complaint-level-bcl-about.md

* Update anti-spam-bulk-complaint-level-bcl-about.md

* Update release-notes-mde-archive.md

Formatting and link fixes

* Link updates

* Build report fixes

* Article alignment (#9176)

Intune procedures standardization and copy/technical edits.

* Update date and improve clarity in overview

Updated the date for the Codename MDASH overview and refined the wording in the 'Prepare' section for clarity.

* Add CallActivityEvents advanced hunting schema reference (#8949)

* Add CallActivityEvents hunting schema reference

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 2879d2fb-b4ab-490b-96cb-e11e4735efe6

* Address CallActivityEvents review feedback

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @Stacyrch140

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Stacy Chambers <102548089+Stacyrch140@users.noreply.github.com>
Copilot-Session: 2879d2fb-b4ab-490b-96cb-e11e4735efe6

* Update ms.date and remove deletion note (#9178)

Bump ms.date to 07/01/2026 and remove the sentence claiming that existing Teams meetings, chats, channels, and calls are deleted after adding a block entry. This clarifies the Tenant Allow/Block List guidance in defender-office-365/tenant-allow-block-list-teams-domains-configure.md.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 91c4341f-a0c5-4d2a-9caf-7a91f19f5ba8

* Clarify Teams mailbox requirements for user reporting (#9179)

* Clarify Teams mailbox requirements

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0008fc20-c9b1-4711-96d3-3c2ea1cc6dd2

* Clarify reporting mailbox restrictions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 0008fc20-c9b1-4711-96d3-3c2ea1cc6dd2

---------

Copilot-Session: 0008fc20-c9b1-4711-96d3-3c2ea1cc6dd2

* Update android-configure (#9188)

Consolidated redundant Intune procedures, copy edit and technical edit.

* Remove line break tag (#9190)

* Chrisda to Main (#9191)

* Update android-configure

Consolidated redundant Intune procedures, copy edit and technical edit.

* Update android-configure.md

* Intune policy standardization

* Update configure-cloud-block-timeout-period-microsoft-defender-antivirus.md

Intune policy standardization, Defender portal policy standardization, and added missing PowerShell procedure.

* Revert "Add Remote tenant group (GDAP) option to URBAC custom role assignment"

* Learn Editor: Update mdash-foundry-integration.md

* Update alerts-mdi-classic.md (#9197)

* Learn Editor: Update alerts-mdi-classic.md

* Learn Editor: Update alerts-mdi-classic.md

* Update alerts-xdr.md (#8902)

* Learn Editor: Update alerts-xdr.md

* Learn Editor: Update alerts-xdr.md

* Learn Editor: Update fixed-reported-inaccuracies.md (#9185)

* Document the DLP to Purview migration tool and non-Microsoft app support (#9203)

Add a section covering the DLP to Purview migration tool: prerequisites,
supported scope, the four wizard steps, post-migration review in Purview,
FAQ, known issues, and wizard screenshots.

Add a Non-Microsoft app support section listing the SaaS apps Purview DLP
supports (Box, Dropbox, Google Workspace, Salesforce) with prerequisites
and a pointer to the Purview documentation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add known limitation for Teams launched from proxied Google Workspace sessions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update advanced-hunting-datasecuritybehaviors-table.md

* Learn Editor: Update advanced-hunting-datasecuritybehaviors-table.md

* Learn Editor: Update defender-sensor-change-log.md

* Learn Editor: Update defender-sensor-change-log.md

* Learn Editor: Update ai-code-security-onboarding.md

* Learn Editor: Update mdash-foundry-integration.md

* Learn Editor: Update mdash-foundry-integration.md

* Learn Editor: Update mdash-foundry-integration.md

* Learn Editor: Update ai-code-security-onboarding.md

* Learn Editor: Update ai-code-security-onboarding.md

* Learn Editor: Update whats-new.md

* Learn Editor: Update whats-new.md

* Learn Editor: Update ai-code-security-onboarding.md

* Learn Editor: Update whats-new.md

* Learn Editor: Update mdash-foundry-integration.md

* Add Remote tenant group (GDAP) option to URBAC custom role assignment

Documents the Remote tenant group option in the Add assignment side pane, enabling GDAP-based cross-tenant URBAC assignment. Feature is live for customers today (2026-08-31) per Eng green light. Resubmission after revert PR #9195.

* Update remediate-vulnerability-findings-vm.md (#9205)

* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Updated published docs with latest contributions (#8824)

* Update identity remediation actions for unified multi-connector support

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Make identity actions section generic and reference remediation actions page

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Use comma-separated values for supported identity sources column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Update roles table with connector columns for identity providers and SaaS apps

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add MDA roles for SaaS apps column and SOC Identity Responder role

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Remove Deactivate and Set account risk actions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add Entra ID roles for Force password change action

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add SOC Identity Responder to Entra ID column for response actions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Reference required permissions page for identity provider column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Add SOC Identity Responder to Defender for Identity response actions permissions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Clarify identity actions span connectors across on-prem, Entra ID, IAM, and SaaS

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Trim identity actions view details to account settings only

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Fix Supported actions table: remove stray SOC role and link column

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Remove SOC Identity Responder from Enable action (not supported)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256

* Learn Editor: Update alerts-containers.md

* Learn Editor: Update alerts-containers.md

* Remove AI Agent write access classification

Removed the description for AI agents with privileged business system write access from the predefined classifications section.

* Learn Editor: Update ai-threat-protection.md

* Move account correlation rules under Settings (#8793)

* Move account correlation rules under settings

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Adjust account correlation navigation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Use full account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Restore original account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* Resize account correlation screenshot

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

---------

Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

---------

Co-authored-by: izauer-bit <76057672+izauer-bit@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: EyalGur74 <160857568+EyalGur74@users.noreply.github.com>
Co-authored-by: Sapir Schneider <296893019+SapirSchneiderService@users.noreply.github.com>
Co-authored-by: Liran Levy <309411196+liran-levy3@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313

* OOB publish for sync PR (#8976)

* Docs: soft rebrand Defender XDR → Defender (batch 612-6) (#8027)

* Docs: soft rebrand Defender XDR → Defender (batch 612-6)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 20 files. Protected references (metadata, includes, UI navigation, image alt text, detection source names, acronym definitions, XDR detection engine names) are preserved.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back Changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix conflict.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/defender-docs (branch public) (#7591)

* Add custom graph cost management link in graph charges section

* Update mdb-faq.yml

Updating public documentation because numerous support cases have been opened due to documentation being unclear. Government customers are not included in this section and should be clarified for customers when trying to understand what licensing is required.

* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live

* Merge for Defender deployment tool GA announcement (#8099)

* Selective Response Actions: update from preview to GA

- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Deleted preview references, got rid of current ga behavior.

* Mentioned the zip / exe choice

* Added what's new entry

* Updated date

* Updated date

* Enhance Sentinel graph visualization documentation (#7904)

* Enhance Sentinel graph visualization documentation

Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.

* Fix formatting and enhance graph visualization section

* Update graph-visualization.md

* docauthoring:copy/edit updates

* updates

* fix

---------

Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#525)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Ofer Schreiber <ofer@bigpanda.io>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update advanced-hunting-emailattachmentinfo-table.md (#307)

Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. `.exe`) while the field is actually a file content type (e.g. `txt;text` or `email;mime` or `png`).

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update advanced-hunting-take-action.md with query reference (#406)

* Update advanced-hunting-take-action.md with query reference

Added Kusto query reference for enabling 'Submit to Microsoft' and 'Initiate automated investigation'. To make it more clear after it was raised in the community

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Update manage-event-based-updates-microsoft-defender-antivirus.md (#345)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* Update with the correct GPO setting name (#365)

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>

* MDB: Update references to the onboarding (#377)

* fix: MDB, update onboarding, rename MAM to WIP

Azure Portal has slowly but progressively been moved to Entra admin center: Update the URL and the actual naming in the portal.

MAM isn't mentioned it seems to be replaced by Windows Information Protection in the same screen.

* fix: Further replace MAM occurrences by WIP 

MAM wording has been removed from both the old Azure portal, as well as in Entra admin center.

* fix: MDB, add updated screenshot MDM and WIP user scopes

While the structure is mostly unchanged, add new screenshot that includes current namings and same design of selector / radio buttons.

* MDB: Include updated screenshot

Include updated screenshot and update description of the picture.

* MDB: Delete old screenshot of MEM/MAM user scope settings

New picture was added with new name, this one is now obsolete.

---------

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Change MDEConfig.txt to DefenderDTconfig.txt (#418)

"DefenderDT.exe -makeconfig" crates a file named DefenderDTconfig.txt instead of MDEConfig.txt

Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Update configure-network-connections-microsoft-defender-antivirus.md (#448)

Fixing broken link for https://learn.microsoft.com/en-us/windows/privacy/manage-windows-1709-endpoints#windows-update

No longer works because of ham-fisted MS redirects.

* Update advanced-hunting-microsoft-defender.md (#343)

Add to "known Issues":
When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting.

Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>

* Fix grammar in Teams block entry instructions (#496)

* Fix grammar in Teams block entry instructions

Blocking a domain does not block the Teams meeting invitation itself. Blocking a domain will remove the user from the Teams meeting chat after the meeting ends. The current documentation (Teams Meetings) may be misleading as to suggest that it affects all meetings.

* Fix grammar in Teams block entry instructions

Corrected grammatical errors in the block entry explanation.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Clarify instructions for running Client Analyzer shipped version  (#498)

* Clarify instructions for running Client Analyzer shipped version in live response

Adjust the format which is clearer for binary version and python version separately.

* Update run-analyzer-linux.md

* Fix formatting and wording in run-analyzer-linux.md

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Update faqs-on-tamper-protection.yml (#532)

Remove bracket so link properly connects to target URL

* Update quarantine-shared-mailbox-messages.md (#528)

* Update quarantine-shared-mailbox-messages.md

Updated wording for clarity and expanded scope to include both shared and user mailboxes.

* Update quarantine management instructions and date

Updated the date for the document and refined the instructions for accessing quarantined messages in shared mailboxes.

* Update shared mailbox quarantine management instructions

Clarified that automapping is no longer required for managing quarantined messages in shared mailboxes. Updated conditions for accessing quarantined messages.

---------

Co-authored-by: Chris Davis <chris.davis@microsoft.com>

* Resolve syncing conflicts from repo_sync_working_branch to public (#529)

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-04) (#8059)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix fictional bookmarks AIRA created

Removed redundant options for enabling UEBA and streamlined the text.

* Remove bookmark to nonexistent content

Removed redundant sentence in the UEBA documentation.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update release-notes-recommendations-alerts.md

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [2/2] (#8088)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix metadata for PIM in MDO configuration document

* Fix metadata for safe attachments configuration doc

* Update ms.custom metadata in documentation

* Fix formatting in submissions admin review document

* Fix formatting for ms.custom in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-06) (#8061)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix bad AIRA edit

Updated section header from 'Next steps' to 'Next step'.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b5) (#8096)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting of ms.custom metadata in document

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8060)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8062)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8072)

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8095)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Clarify that the Risky IP address category is dynamic (#8198)

* Clarify that the Risky IP category is dynamic and can expire

Add a note explaining that the Risky category is assigned automatically
based on threat intelligence and is removed if no further malicious
activity is detected. All other categories are assigned manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: AbbyMSFT <88824859+AbbyMSFT@users.noreply.github.com>

* Apply suggestion from @AbbyMSFT

* Apply suggestion from @AbbyMSFT

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* new onboarding (#7970)

* new onboarding

* updates

* updates

---------

Co-authored-by: Regan Downer <v-rdowner@microsoft.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-usp-test8a-mberdugo) (#8077)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 4

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Remove AIRA-duplicated ai-usage metadata

Removed 'ai-usage' line from the document header.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Update approval functionality (#8303)

* Update approval functionality (#8304)

* docs(sentinel): add parameterized notebook jobs

Adds overview and detailed guidance for parameterized notebook jobs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md

* WI591424: GA transition for serverless containers docs

* Restore historical preview note and keep separate GA release note

* Move June 25 GA note to top of table and section list

* Document Registry access requirement for full Serverless Containers features

* Update defender-for-cloud/release-notes.md

* Update defender-for-cloud/release-notes.md

* Mark Serverless Containers as supported in Defender portal

* Move serverless containers GA date to July 1

* Place July 1 release note under July table

* Set July 1 ms.date across remaining PR pages

* Version 26.1.1 (#8316)

* Version 26.1.1

* Fixes

* Mapping updates to transition from grouped to individual recommendations (#8151)

* Transition from grouped to individual recommendations

* Update transition article with end-state classification for deprecated assessments

- Add explanation of 3 end-states (dynamic substitute, static substitute, no substitute)
- Add End-state and New assessment ID columns to all reference tables
- Change 'NA (Static)' to 'Unknown' in Category column for static substitutes (EDR, SQL)
- Mark EDR and SQL rows as static substitutes with [TBD] new assessment IDs
- Fix HostMisconfiguration → HostMisconfigurations per category list
- Mark GitHub security posture management row as [TBD] pending DevOps partner input
- Add placeholder section for Microsoft Defender for Identity (pending partner review)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date and clarify static substitute guidance

- Add July 31, 2026 as the grouped recommendation deprecation date
- Clarify that static substitute recommendations use 'Unknown' category
  and users should filter by assessment ID, not category filter

Per meeting with Roy Hirsch (June 21, 2026)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Revert "Add July 31 deprecation date and clarify static substitute guidance"

This reverts commit c4f487921093d967d968310ed5e2773e07cf3291.

* Update grouped-to-individual recommendations article per Roy Hirsch review

- Remove IcM routing column from all tables (internal-only, not customer-facing)
- Fix ARG query field: securityCategories -> recommendationCategory
- Fix category name: 'Vulnerabilities' -> 'SoftwareUpdate' recommendation category
- Replace 'assessment key/ID' with 'recommendation ID' throughout
- Replace 'grouped assessment' with 'grouped recommendation' throughout
- Remove 'No substitute' end-state (deprecated items not included in this guide)
- Split each product table into Dynamic substitutes and Static substitutes sections
- Simplify table columns: Dynamic (Recommendation | Recommendation ID | Category),
  Static (Recommendation | Recommendation ID | New recommendation ID)
- Remove IcM routing reference from intro tip and reference section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename 'Recommendation category reference' to 'Recommendation transition reference'

Section now covers both dynamic (category-based) and static (recommendation ID-based)
transitions, so 'category reference' was no longer accurate.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add July 31 deprecation date to transition guides

- Add July 31, 2026 deprecation date in transition-grouped-individual-recommendations.md
  (overview callout, adopting section, what you should do now callout)
- Add July 31, 2026 deprecation date in transition-disable-rules-exemptions.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update transition guide with Roy's final feedback

- SQL databases/servers recs: mark as deprecated, replace static substitute table with note and link to full SQL recommendations reference
- Containers: add Azure (c609cf0f) and AWS (682b2595) running container images as dynamic substitutes mapped to SoftwareUpdate
- GitHub security posture mgmt (fd104c01): update [TBD] with link to full DevOps recommendations reference
- Linux secure boot rec (ad50b498): not added (status unknown per Roy)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix SQL recommendations link to point to VA rules mapping article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Replace internal substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply manual edits and re-apply terminology changes

- Remove Secure Score row from comparison table
- Update vulnerability management example description
- Rename old query label and add note before new query
- Remove Secure Score during transition section
- Change EDR recs to deprecated recommendations
- Replace Dynamic/Static substitute terms with plain descriptions

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix terminology: replace 'Dynamic substitutes' with 'Replaced by individual recommendations' in Containers and DevOps sections; fix garbled text and table in Servers deprecated section

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix files moved in error (#8310)

* fix files moved in error

* fixes

* [AIRA] Bot Remediation - AbbyMSFT (defender-docs-pr, 20260615-dfi-root-b-r1) (#8073)

* fix(COPY-EDIT): batch

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b3) (#8094)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix ms.custom field formatting in documentation

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8074)

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Restructure MDA TOC around customer journey (#7505)

* Restructure MDA TOC around customer journey

Reorganize from feature-based sections to a lifecycle flow:
Deploy > Connect and discover > Assess risk > Control and protect >
Detect threats > Investigate and respond > Stream to SIEM > Manage

Key changes:
- Dissolve app governance silo into relevant phases
- Merge 'View and manage applications' into discovery
- Merge 'Information protection' into 'Control access and protect data'
- Move AI agent protection into discovery section
- Rename SIEM section to clarify outbound direction
- Move operations guide into 'Manage and configure'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename section to 'Investigate and respond to threats'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add PR target instruction to copilot-instructions.md

Ensure PRs are always created against MicrosoftDocs/defender-docs-pr
rather than the fork.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Move app governance setup articles to appropriate sections

- 'Turn on app governance' moves into Configuration (it's a config task)
- 'Get started with app governance' moves into 'Discover and manage
  OAuth apps' (it's a product walkthrough, not deployment)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply content audit: move articles to correct lifecycle phases

Based on full-content audit of 35 cross-cutting articles:

Moved to 'Control access and protect data':
- manage-app-permissions.md (renamed to 'Manage OAuth app permissions')
- app-governance-visibility-insights-sensitive-content.md
- governance-discovery.md
- mde-govern.md
- ai-agent-protection.md and real-time-agent-protection (AI agent protection)

Moved to 'Investigate and respond to threats':
- app-governance-anomaly-detection-alerts.md
- app-governance-investigate-predefined-policies.md
- tutorial-flow.md (response automation, not SIEM)

Kept ai-agent-inventory.md in discovery (primary entry point).
AI agent discovery stays in Connect and discover; protection moves
to Control access.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Rename discovery sections for clarity

- 'Discover cloud apps (shadow IT)' -> 'Discover cloud apps and shadow IT'
- 'Discover and manage OAuth apps' -> 'Discover and manage OAuth apps with app governance'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Restructure MDA TOC: split discover/connect, rename access section

- Split 'Connect and discover apps' into separate 'Discover apps' and
  'Connect apps' sections, with discovery first
- Rename 'Control access and protect data' to 'Manage access and app behavior'

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Consolidate app governance articles and clarify OAuth app scope in titles

- Flatten Connect apps TOC node (remove unnecessary intermediate level)
- Consolidate app governance articles:
  - Merge policies overview + get-started + predefined into single overview
  - Merge policies create + manage into single create-and-manage article
  - Merge threat detection overview + get-started + monitor into single article
  - Merge visibility insights overview + get-started into single article
- Update all app governance TOC nodes and article titles to include 'OAuth'
  to distinguish from SaaS app content
- Add redirects for 6 deleted articles
- Fix all internal links to deleted articles

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix broken links in index.yml to deleted articles

Update references to consolidated app governance articles that were
deleted upstream.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Resolve PR review blocking issues: typos, casing, and alt-text fixes

- Fix 'polcies' typo in alt-text (app-policies-overview)
- Add graphic-type prefix to two image alt-texts (app-policies-overview)
- Lowercase 'app governance' in alt-text (detect-remediate-overview)
- Remove duplicate 'the' (secure-apps-access-non-graph-api)
- Lowercase three 'app governance' instances (anomaly-detection-alerts)
- Title case 'Zero Trust' (index.yml)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): batch (#8075)

Remediation for COPY-EDIT.
Files affected: 6

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-usp-test8a-guywi) (#8076)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title and content in mto-requirements.md

Renamed 'Next steps' section to 'Related content' and updated its content.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8078)

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-b) (#8081)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Improve formatting of simulation automation steps

Formatted the configuration steps into a bulleted list for better readability.

* Update attack-simulation-training-training-campaigns.md

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Update ms.custom metadata in connectors-remove-blocked.md

* Refactor ms.custom metadata in documentation

Updated ms.custom metadata to include a list format.

* Update ms.custom formatting in documentation

* Update ms.custom format in preset-security-policies.md

* Update quarantine-admin-manage-messages-files.md

* Fix formatting of ms.custom property in markdown

* Update ms.custom metadata format in markdown file

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* WI590578-table-insights (#8265)

* WI590578-table-insights

* quality fixes

* additional work

* updated conceptual page

* page quality fixes

* Refine Table insights guidance and restore Data Lake terminology

* Update manage-table-tiers-retention.md

* fixes to instructions

* Update manage-table-tiers-retention.md

* quality fixes

* fix

* fix title

* small fixes

* small fixes

* fix based on Nikita's comment

actually I realized there is one more change when in Whats new section when you click on tables, you can see data sources in side drawer.

* fixing broken list

---------

Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-d) (#8083)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 9

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Fix formatting for ms.custom in alert policies document

* Fix formatting for ms.custom in audit log document

* Fix formatting of ms.custom in documentation

* Fix formatting in connection filter policies document

* Fix formatting in connectors-detect-respond-to-compromise.md

* Remove section for new Microsoft 365 administrators

Removed unnecessary section for new Microsoft 365 administrators and related content. There were no links or anything of value. It was essentially an ad, and even that ad didn't link to anything.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Document AI agent awareness for Entra ID service principals

- Add Used by AI agents (Preview) column to NHI details table
- Add Used by AI agents (Preview) stat to NHI insight cards
- Add what's-new entry for AI agent visibility

Work item: 591169

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Chrisda to Main (#8323)

* Update attack-surface-reduction-rules-reference.md

Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'

* Update attack-surface-reduction-rules-overview.md

Consistency updates

* ASR rules report screenshot updates

More data

* Remove A3 from E3 gets MDO P1 refs

Per request

* Added Teams to report suspicious

* Update outbound-spam-high-risk-delivery-pool-about.md

Content VSO 591495

* [AIRA] Bot Remediation - dansimp (defender-docs-pr, d365-test8b-dansimp) (#8085)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update email-analysis-investigations.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - deniseb (defender-docs-pr, d365-test8b-deniseb) (#8086)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 1

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update authorship information in documentation

* Change section title to 'Related content'

Updated section title and added related content links.

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Denise Vangel-MSFT <deniseb@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [1/2] (#8087)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Fix formatting in air-report-false-positives-negatives.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-e) [2/2] (#8090)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 8

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* Apply suggestion from @GitHubber17

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* [AIRA] Bot Remediation - unowned (defender-docs-pr, em-test8d) (#8091)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 2

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Apply suggestions from code review

Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>

* fix(COPY-EDIT): editorial (#8089)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* CFA article updates (#8149)

* Configure controlled folder access

* Added Windows Security app procedures

And removed them elsewhere

* CFA overview article rename

* CFA

* CFA Overview

* Delete customize-controlled-folders.md

* Removed CFA article from MDB

And also cleaned up ASR/ASR rule references and links, including any Intune procedure links.

* Link and link title updates for CFA

* Update address-unwanted-behaviors-mde.md

* New monitor CFA article

Remnants of the old evaluate CFA article + Windows event viewer steps/info from the CFA overview article.

* Copy and Technical edits

* CFA demonstrations

* CFA demos

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* CFA/ASR demo updates

* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md

* Final edits

* Offending file name renames

Per build report

* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-c) (#8082)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update address-compromised-users-quickly.md

* Fix formatting of ms.custom metadata in markdown

* Fix formatting of custom metadata in markdown file

* Correct 'ms.custom' formatting in documentation

Fixed formatting of the 'ms.custom' metadata entry.

* Update custom metadata in mdo-portal-permissions.md

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8053)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* docs(sentinel): add parameterized notebook job guidance

Add steps for defining notebook parameters, refreshing job parameters, and overriding values when running a notebook job manually.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 11) - NEW SERIES, IGNORE BATCH NUMBER (#7939)

* Docs: soft rebrand Defender XDR to Defender (batch 11)

Replace 'Defender XDR' and 'Microsoft Defender XDR' with 'Defender' and
'Microsoft Defender' in body text of 20 advanced hunting schema and
feature articles, per Microsoft Defender branding guidelines.

Preserved unchanged:
- appliesto metadata fields
- [!INCLUDE references
- ms.service and other metadata fields
- Link display text referencing external page titles
- URL paths and fragments

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back change.

Updated description to specify Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-2) (#8016)

* Docs: soft rebrand Defender XDR → Defender (batch 612-2)

Update 18 advanced hunting files to replace 'Defender XDR' and
'Microsoft Defender XDR' with 'Defender' and 'Microsoft Defender'
in body text per branding guidelines. Protected references
(metadata, includes, API names, historical records, plugin names)
are left unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back change.

* Roll back change.

* Roll back change.

Updated the description to include 'XDR' in the title.

* Roll back change.

* Roll back changes.

Updated references to Microsoft Defender XDR in the document.

* Roll back changes.

Updated references from Microsoft Defender for Endpoint to Microsoft Defender XDR in the migration guide.

* Roll back changes.

* Roll back changes.

Updated title and references to reflect Microsoft Defender XDR.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Docs: soft rebrand Defender XDR → Defender (batch 612-9) (#8030)

* Docs: soft rebrand Defender XDR → Defender (batch 612-9)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 10 files. 1 file had no eligible changes (all XDR refs were protected product names).

Protected references preserved: metadata fields, [!INCLUDE] lines, image alt text, historical changelog entries in whats-new.md, API endpoint names, external blog post titles, 'Defender Experts for XDR' product name, XDR capability descriptions (XDR solution, XDR tools, XDR/SIEM).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

* Roll back changes.

Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR, including changes to titles and descriptions throughout the content.

* Roll back changes.

* Roll back changes.

* Roll back changes.

* Fix typo in Microsoft Defender XDR description

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>

* Fix directory path and update checksum commands (#8334)

Command errors caused by folder structure or incorrect quotation/space within a zip file.

* Clarify prerequisites for attack disruption exclusions based on Unified RBAC state (#8276)

Split the Prerequisites section into Device and Identity exclusion
permissions, showing the required roles when Unified RBAC is enabled
versus disabled. Cross-link to Unified RBAC activation and custom
permissions docs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix attack disruption docs: simplify TOC title and table entries (#8341)

- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update value-data-connectors.md with onboarding notes (#8254)

* Update value-data-connectors.md with onboarding notes

Added note about device onboarding requirements and limitations.

* Apply suggestion from @DebLanger

* Update date and permissions in get-machines.md (#8344)

Updated the date and permissions section in the API documentation.

* wi-589516: Remove '| Microsoft Docs' suffix from title metadata (#8255)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>

* Update email post delivery events documentation

* Learn Editor: Update fixed-reported-inaccuracies.md (#8308)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA (#8354)

* DisruptionAndResponseEvents table in the advanced hunting schema - GA

* Updating what's new

* Removing preview note

* Docs: soft rebrand Defender XDR → Defender (batch 2) (#8191)

* Docs: soft rebrand Defender XDR → Defender (batch 2)

Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR'
with 'Defender' in eligible locations per branding guidelines.

Files updated:
- critical-asset-management.md (1 replacement)
- get-started-exposure-management.md (4 replacements)
- prerequisites.md (3 replacements)
- whats-new.md (0 - all references in historical What's New entries)

Preserved XDR references in:
- Bold UI navigation paths (prerequisites.md line 67)
- Historical What's New entries (whats-new.md lines 179, 310)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Roll back changes.

* Roll back changes.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Docs: soft rebrand Defender XDR → Defender (batch 13) (#7941)

* docs: soft rebrand Defender XDR → Defender (batch 13)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* roll back change.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers (#8350)

* Document Security findings (Preview) Azure Policy limitation in Defender for Containers

- Add limitation note to Security findings (Preview) component in AKS, EKS, and GKE tabs
  stating it cannot be enabled through Azure Policy and must be toggled in plan Settings
- Rename 'Security findings' to 'Security findings (Preview)' for accuracy
- Remove 'This article explains' from opening line per style guide

Addresses US585115 / IcM 662676555 / CxE WI 19929

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestions from code review

Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add identity assessment key mappings to transition reference article (#8351)

* Add identity assessment key mappings to transition reference article

Replace placeholder in Microsoft Defender for Identity section with
assessment key mapping table for 5 guest/disabled account assessments.
Uses 'assessment' terminology per Roy's guidance.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8050)

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* fix(COPY-EDIT): editorial (#8048)

Remediation for COPY-EDIT.
Files affected: 7

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentinel-mberdugo-02) (#8047)

* fix(COPY-EDIT): editorial

Remediation for COPY-EDIT.
Files affected: 10

Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv

* Update section title from 'Next steps' to 'Related content'

* Fix formatting of title in integration guide

---------

Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>

* Cloud security reporting GA (#8267)

* Cloud security reporting GA: remove preview, add release note and card customization

- Remove (Preview) from title and H1 in cloud-security-reporting.md
- Remove preview features prerequisite
- Add card customization capability
- Add June 30 GA release note entry

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add customize cards section with screenshots to cloud reporting article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Clarify that card customization is only for cards labeled Customizable

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add migration guidance for Sentinel incident creation rules to Defender alert grouping (#7952)

* Add Sentinel-to-Defender alert grouping migration guidance

* Relocate Sentinel migration article to unified-secops docset

* Update migration images and include restored xdr article copy

* Remove duplicate defender-xdr migration article copy

* Update image alt text for incident correlation migration doc

* Fix validation issues for incident correlation migration docs

* Fix broken migration link and update image references

* israel review

* Fix PR validation issues for links, metadata, and image naming

* Fix broken unified secops migration links

* Remove image from incident creation migration article

* Remove unused onboarding image file

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Fix broken cross-docset link to migrate-sentinel-incident-creation-rules-alert-grouping

* Revert to correct cross-docset URL link for new migrate-sentinel article

* Revert to correct cross-docset URL link for new migrate-sentinel article

---------

Co-authored-by: Guy Wild <98332688+guywi-ms@users.noreply.github.com>

* Clarify DlpInfo description in deviceinfo table

Updated DlpInfo description to clarify its content and added a reference link for further information.

* GA multicloud recommendations June 30: release notes, score impact, new tag docs, reference updates (#8275)

* Docs: GA multicloud recommendations June 30 - score impact, new tag, ref updates

- Add June 30 GA release note for expanded multicloud coverage
  (~150 recommendations, ~90 resource types, score impact)
- Add GA/Preview rows to recommendations release notes
- Document 'New' tag (30-day window), change log, and portal banner
  in review-security-recommendations.md (both portal pivots)
- Add Secure Score impact callout to secure-score-security-controls.md
- Remove (Preview) from 217 multicloud recommendations across 6
  reference files (networking, data, identity-access, app-services,
  compute, container)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix: restore deleted category tabs and select step in review-security-recommendations.md

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

* Apply suggestion from @DebLanger

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix DlpInfo reference link in deviceinfo-table.md

Updated the reference link for DlpInfo properties to ensure it points to the correct documentation.

* Add event-driven response guide for Defender for Storage malware scanning (#8345)

- Expand Event Grid setup walkthrough in configure-malware-scan article with 3-step process
- Add 3 Azure Functions templates: quarantine, auto-delete, and alert/notification
- Add sample payloads for No threats found and Not Scanned result types
- Add event delivery troubleshooting section covering permissions, networking, and subscription validation
- Add Event-driven response feature bullet to introduction article

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Align identity risk score GA heading with what's-new convention

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add Widespread Local Admin predefined classification rules (#8289)

* Add Widespread Local Admin classification rules and release note

- Add three new Identity classification rules to predefined classifications:
  Widespread Local Admin on Servers (High), Widespread Local Admin on
  Workstations (High), and Widesprea…
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants