Loading...

Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities

Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities

Microsoft Defender for Cloud Apps is replacing the legacy “Activity performed by terminated user” alert with a dynamic detection model called “Activity by a deprovisioned user (preview)” starting late June 2026. This improves detection accuracy, adapts to threats, requires no manual setup, and may change alert behavior over time. What and Why Microsoft Defender for Cloud Apps is enhancing its threat protection capabilities by migrating legacy detection policies to a new dynamic detection model. This update improves detection accuracy, reduces false positives, and enables faster response to evolving threats by using research-driven detections maintained by Microsoft security experts. As part of this change, the legacy alert “Activity performed by terminated user” is being replaced by a detection built on the new dynamic detection model. This updated detection is designed to more precisely identify risky activity associated with users who have left the organization while continuously adapting to changes in the threat landscape. This change also introduces a shift from static detection logic to continuously updated detection logic, which may evolve over time to improve signal quality and accuracy. Rollout Schedule General Availability (Worldwide, GCC, GCC High, DoD): We will begin rolling out in late June 2026 and expect to complete by early July 2026. Impact on your organization Who is affected Organizations using Microsoft Defender for Cloud Apps threat protection capabilities Security operations center and IT security teams Platforms and services Microsoft Defender for Cloud Apps, part of Microsoft Defender XDR What will happen The legacy alert “Activity performed by terminated user” will be replaced by a detection built on the new dynamic detection model, titled “Activity by a deprovisioned user (preview).” The suffix will be removed next month. The updated detection will: Be enabled by default Be automatically maintained and updated by Microsoft Continuously evolve to improve detection accuracy and adapt to emerging threats Detection behavior, alert patterns, or alert volume may change over time as the model adapts. No manual configuration is required. During rollout: Disabled legacy policies may remain temporarily visible, and  Legacy policies will be removed after migration completes as part of the retirement of the legacy […]

The post Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft OneDrive and SharePoint: Generate smart tables of contents for PDFs on the web with Copilot

Microsoft 365 Copilot users can generate AI-created, hierarchical, clickable tables of contents for PDFs in OneDrive and SharePoint on the web...

1 hour ago

Microsoft Defender for Office 365: Changes to Unified RBAC permission mapping for Microsoft Entra Security Operator role

Microsoft is updating Microsoft Defender for Office 365’s Unified RBAC mapping for the Microsoft Entra Security Operator role, removing ...

1 hour ago

Microsoft 365 Copilot: new guided Copilot onboarding experience

Microsoft 365 Copilot introduces an optional, admin-enabled guided onboarding experience for Frontier participants starting late October 2026....

1 hour ago

Microsoft Purview |Unified Classification Management Experience

Microsoft Purview is launching a unified Classification Management experience for admins to manage classifiers consistently. Public Preview st...

1 hour ago

Microsoft Purview | Data Loss Prevention: Administrative Units support for DLP policies for Microsoft Copilot

Microsoft Purview extends Microsoft Entra Administrative Units support to Copilot DLP policies, enabling delegated management within units whi...

1 hour ago

Action required: Update Teams devices to a minimum app version ahead of the retirement of Exchange Web Services (EWS)

Update Microsoft Teams Rooms on Android, phones, and panels to the minimum app version released in February 2026 before October 2026 to avoid ...

1 hour ago

Microsoft Power Platform governance and administration – Secure Dataverse record with column-based filtering

We are announcing the ability for admins to use filtered views to select and manage record-level access securely by defining security based on...

1 hour ago

Microsoft Teams: Impersonation Protection for Teams meetings

Impersonation Protection for Teams meetings helps users identify potentially deceptive participants and meeting organizers. When Teams detects...

1 day ago

Microsoft Copilot (Microsoft 365): Use Dataverse Business Skills in Sales Agent

Business Skills are natural language instructions authored and stored in Microsoft Dataverse that teach Sales Agent how work gets done within ...

1 day ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.