Blog Post

Microsoft Defender XDR Blog
5 MIN READ

Monthly news - April 2025

HeikeRitter's avatar
HeikeRitter
Icon for Microsoft rankMicrosoft
Apr 07, 2025
Microsoft Defender XDR
Monthly news
April 2025 Edition
This is our monthly "What's new" blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this edition, we are looking at all the goodness from March 2025. Defender for Cloud has it's own Monthly News post, have a look at their blog space.
 
April 9th & 10th is Microsoft Secure! Make sure you join this virtual event to hear about our latest product announcements. 

Three broadcast times are available, offering opportunities to get your questions answered by subject matter experts at a time that suits you best.

April 9, 2025 | 8:00 AM – 9:00 AM PT (UTC-7) | Americas broadcast
April 10, 2025 | 10:00 AM – 11:00 AM CET (UTC+1) | Europe, Middle East, Africa broadcast
April 10, 2025 | 12:00 PM – 1:00 PM SGT (UTC+8) | Asia broadcast

Microsoft Secure - Home - Microsoft Secure registration home page.
 
 

New episodes of the Virtual Ninja Show has been published, covering various products and scenarios.

 

Unified Security Operations Platform: Microsoft Defender XDR & Microsoft Sentinel

  • (GA Announcement) The content hub offers the best way to find new content or manage the solutions you already installed, now with granular AI search. 
  • (Public Preview) The Microsoft Sentinel agentless data connector for SAP and related security content is now included, as public preview, in the solution for SAP applications.
  • Blog post: Transforming public sector security operations in the AI era
    Discover how Microsoft's AI-powered, unified SecOps can revolutionize public sector security operations and safeguard multiplatform, multi-cloud environments with industry-leading innovation and seamless integration. Ready to elevate your cyber defense?
  • (Public Preview) The incident description has moved within the incident page. The incident description is now displayed after the incident details. For more information, see Incident details.
  • You can now link Threat analytics reports when setting up custom detections. Learn more

 

Microsoft Defender for Endpoint

  • Update to the Microsoft Defender Antivirus group policies documentation. Learn more

 

Microsoft Defender for Office 365

  • User reported messages by third-party add-ins can be sent to Microsoft for analysis: In user reported settings, admins can select Monitor reported messages in Outlook > Use a non-Microsoft add-in button. In the Reported message destination section, select Microsoft and my reporting mailbox, and then provide the email address of the internal Exchange Online mailbox where user-reported messages by the third-party add-in are routed to. Microsoft analyzea these reported messages and provides result on the User reported tab of Submissions page at https://security.microsoft.com/reportsubmission?viewid=user.
  • Create allow entries directly in the Tenant Allow/Block List: You can now create allow entries for domains & addresses and URLs directly in the Tenant Allow/Block List. This capability is available in Microsoft 365 Worldwide, GCC, GCC High, DoD, and Office 365 operated by 21Vianet.

Microsoft Defender for Cloud Apps

  • (GA) Unified Identity inventory now general available. Learn more
  • Defending against OAuth based attacks with automatic attack disruption. Microsoft’s Automatic attack disruption capabilities disrupt sophisticated in-progress attacks and prevent them from spreading, now including OAuth app-based attacks. Attack disruption is an automated response capability that stops in-progress attacks by analyzing the attacker’s intent, identifying compromised assets, and containing them in real time. 
  • Level Up Your App Governance With Microsoft Defender for Cloud Apps Workshop Series

    Join one of these workshops to learn:

    • Real-world examples of OAuth attacks
    • New pre-built templates and custom rules to simplify app governance
    • How to quickly identify and mitigate risks from high-risk or suspicious apps
    • Best practices for operationalizing app governance to improve your security posture

    These workshops are designed to accommodate global participation, with flexible date and time options.

  • Protecting SaaS apps from OAuth threats with attack path, advanced hunting and more. Read this blog post to learn about various new capabilities rolling out over the next few weeks.  

Microsoft Defender for Identity

  • Blog post: Discover and protect Service Accounts with Microsoft Defender for Identity
  • Microsoft Defender for Identity now includes a Service Account Discovery capability, offering you centralized visibility into service accounts across your Active Directory environment.
  • New health issue for cases where sensors running on VMware have network configuration mismatch.
  • The Identities page under Assets has been updated to provide better visibility and management of identities across your environment.
  • New LDAP query events were added to the IdentityQueryEvents table in Advanced Hunting to provide more visibility into additional LDAP search queries running in the customer environment.

Microsoft Security Blogs

Threat Analytics (Access to the Defender Portal needed)

 

Updated Apr 07, 2025
Version 2.0
OSZAR »