Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities
Microsoft Defender for Cloud Apps will expand its dynamic threat detection model in November 2025, replacing legacy policies with more accurate, research-driven detections. This update improves threat detection accuracy and responsiveness, requires no admin action before rollout, and includes new detections enabled by default. To improve threat detection accuracy and responsiveness, Microsoft Defender for Cloud Apps is expanding its dynamic model for threat protection. This update enhances the signal-to-noise ratio (SNR) of detections and enables faster adaptation to emerging threats, helping security teams stay ahead of evolving risks. This rollout continues the migration of legacy threat detection policies, following the first batch announced in Message center post MC1061724. The second batch introduces new detections that replace several legacy policies, further aligning with our goal of delivering more precise, research-driven protection. When this will happen: General Availability (Worldwide, GCC, GCC High, DoD): Rollout begins early November 2025 and is expected to complete by the end of November 2025. How this affects your organization: Who is affected: Organizations using Microsoft Defender for Cloud Apps, including tenants in Worldwide, GCC, GCC High, and DoD environments. What will happen: The dynamic model will be expanded to include additional research-driven detections. These detections are continuously updated by Microsoft security researchers to reflect the evolving threat landscape. Detections may be added, removed, or modified dynamically to ensure optimal protection. These are research-driven and enabled by default, requiring no manual configuration. The second batch of legacy policies being migrated includes: “Unusual ISP for an OAuth App” “Suspicious file access activity (by user)” These will be replaced with the following detections: Replacing “Unusual ISP for an OAuth App”: “OAuth application activity from an unknown ISP (Preview)” Replacing “Suspicious file access activity (by user)”: “Suspicious file access from untrusted ISP and user agent with malicious IP indicator (Preview)” “Suspicious file access indicative of lateral movement (Preview)” Adding new detection “Activity from a password-spray associated IP address (Preview)” These new detections are already available to you in Preview; the “(Preview)” suffix will be removed once legacy policies are disabled. Governance actions configured on legacy policies will be disabled. Admins can […]
The post Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft 365 admin center: Data Quality Report for Profile Data
Microsoft 365 Organizational Data Services is introducing a new data quality report that helps administrators assess the coverage and health o...
Expanding memory integrity protection across Windows devices
Beginning in October 2026, Windows quality updates will start enabling memory integrity on more eligible Windows devices. On some devices, thi...
Dynamics 365 Project Operations – Update correction journal usability
We are announcing the ability to make different corrections within the same journal, correct a wider range of fields, and easily select transa...
Microsoft Power Automate – View unattended run video logs in portal
We are announcing the ability for users to access video logs for unattended desktop flow runs directly from the portal, improving troubleshoot...
Microsoft Power Platform governance and administration – Secure Dataverse record with column-based filtering
Update: Release of this feature has been updated. We are announcing the ability for admins to use filtered views to select and manage record-l...
Dynamics 365 Project Operations – Reconcile project accrued revenue
We are announcing the ability to reconcile project accrued revenue in Dynamics 365 Project Operations. This feature will reach general availab...
Dynamics 365 Customer Service -Resolve customer emails autonomously with AI
We are announcing the ability to use AI to drive autonomous email resolution in Dynamics 365 Customer Service. This feature will reach general...
Dynamics 365 Contact Center – Use redesigned embedded CSR widget for Contact Center
We are announcing the redesigned embedded customer service representative (CSR) widget in Dynamics 365 Contact Center. This enhancement will r...
Dynamics 365 Project Operations – Use time zone-agnostic fields in resource planning
We are announcing the ability to use time zone-agnostic fields in resource planning in Dynamics 365 Project Operations. This feature will reac...
Dynamics 365 Project Operations – Use what-if analysis on estimates
We are announcing the ability to use what-if analysis on estimates in Dynamics 365 Project Operations. This feature will reach general availab...