| MC1402307 | Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities |
|---|
| Classification | planForChange | ||||||
|---|---|---|---|---|---|---|---|
| Last Updated | 06/23/2026 22:07:28 | ||||||
| Start Time | 06/23/2026 22:07:15 | ||||||
| End Time | 08/07/2026 07:00:00 | ||||||
| Message Content |
[What and Why] Microsoft Defender for Cloud Apps is enhancing its threat protection capabilities by migrating legacy detection policies to a new dynamic detection model. This update improves detection accuracy, reduces false positives, and enables faster response to evolving threats by using research-driven detections maintained by Microsoft security experts. As part of this change, the legacy alert “Activity performed by terminated user” is being replaced by a detection built on the new dynamic detection model. This updated detection is designed to more precisely identify risky activity associated with users who have left the organization while continuously adapting to changes in the threat landscape. This change also introduces a shift from static detection logic to continuously updated detection logic, which may evolve over time to improve signal quality and accuracy. [Rollout Schedule] General Availability (Worldwide, GCC, GCC High, DoD): We will begin rolling out in late June 2026 and expect to complete by early July 2026. [Impact on your organization] Who is affected
Platforms and services
What will happen
Screenshot 1: Screenshot 2: [Action Required/Recommendations] No action is required. Recommended steps:
Learn more: (To be updated closer to rollout.) Create Defender for Cloud Apps anomaly detection policies | Microsoft Defender for Cloud Apps | Microsoft Learn [Compliance considerations]
|

