Loading...

Upcoming retirement of select threat detections in Microsoft Defender for Cloud Apps

Upcoming retirement of select threat detections in Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps will retire select IaaS and PaaS threat detections by mid-May 2026 due to low impact, focusing on identity-related threats. Affected alerts and policies will be removed, but historical data remains accessible. No admin action is required, though updating related processes is recommended. Introduction Microsoft Defender for Cloud Apps is retiring a small set of Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) threat detections. These detections no longer align with the current threat protection scope of Defender for Cloud Apps, which is focused on identity-related threats across Entra, on‑premises, and SaaS environments. Following internal review, these detections are being retired due to low prevalence and low customer impact, allowing us to focus engineering investment on higher-value and more common threat scenarios. When this will happen: General Availability (Worldwide, GCC, GCC High, DoD): Retirement begins early May 2026 and is expected to complete by mid‑May 2026. How this affects your organization: Who is affected: Administrators using Microsoft Defender for Cloud Apps Organizations that rely on the affected IaaS and PaaS detections What will happen: Alerts Suspicious creation activity for cloud region Suspicious change of CloudTrail logging service Multiple storage deletion activities Behaviors Multiple virtual machine (VM) creation activities Multiple delete VM activities After the phase‑out These detections will no longer generate alerts or behaviors. The related built‑in policies will be removed from the Policy management page. Alerts and behaviors already generated will not be deleted and will remain available in: Alerts and Incidents pages Advanced Hunting tables (for historical investigation and auditing) Any existing alert links that previously pointed to these policies will indicate that the policy has been deleted. What you can do to prepare: Compliance considerations: No admin action is required. If you currently reference these detections in operational processes, playbooks, or documentation, we recommend reviewing and updating those materials ahead of the removal date. This change modifies how admins can monitor and report on specific Defender for Cloud Apps detections. Historical alert and hunting data remains available for auditing. Message ID: MC1254554

The post Upcoming retirement of select threat detections in Microsoft Defender for Cloud Apps appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Upcoming retirement of select threat detections in Microsoft Defender for Cloud Apps

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Copilot (Microsoft 365): Local inferencing

Local inferencing expands Microsoft Copilot’s sovereign controls by enabling AI inferencing for supported Copilot interactions to occur within...

2 days ago

Dynamics 365 Customer Service: Quality evaluation supports knowledge source in criteria

Criteria questions can now use knowledge sources to help evaluate customer interactions. This allows organizations to ground evaluation criter...

2 days ago

Microsoft Viva: Ability for leaders to publish Power BI reports

Microsoft Viva Insights is extending its report publishing capabilities from analysts to leader personas such as Chief Officers, Managers and ...

2 days ago

Dynamics 365 Customer Service: Detailed quality evaluation score breakdown

Evaluation details now include a scoring breakdown at the overall, section, and question level. Users can see how the final evaluation score w...

2 days ago

Dynamics 365 Customer Service: Support Not Applicable answer option for quality evaluation criteria

Criteria questions now support a Not Applicable answer option. When a question is marked as not applicable, it is excluded from scoring instea...

2 days ago

Dynamics 365 Customer Service: Inactivate quality evaluation records

Quality managers can now inactivate evaluation records that should no longer contribute to scoring or reporting. Inactive evaluations are pres...

2 days ago

Microsoft Teams: Granular Conditional Access for Teams meetings

Granular Conditional Access for Teams meetings gives organizations greater control over access to sensitive meetings. Administrators can apply...

2 days ago

Customized PowerBI reports behavior after major report updates

Microsoft Viva Insights customized Power BI reports will remain tied to their original report versions and won’t auto-update with major report...

2 days ago

Microsoft SharePoint: Changes to the FAQ web part authoring experience

The SharePoint FAQ web part will shift AI-assisted FAQ creation to Copilot in SharePoint, while retaining manual FAQ editing in the web part. ...

2 days ago

Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions

Microsoft 365 Copilot’s federated connectors will support create, update, and delete actions in third-party services starting October 20...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.