Blog Post

Microsoft Defender XDR Blog
4 MIN READ

Monthly news - June 2025

HeikeRitter's avatar
HeikeRitter
Icon for Microsoft rankMicrosoft
Jun 05, 2025

Microsoft Defender XDR
Monthly news - June 2025 Edition

This is our monthly "What's new" blog post, summarizing product updates and various new assets we released over the past month across our Defender products. In this edition, we are looking at all the goodness from May 2025. Defender for Cloud has it's own Monthly News post, have a look at their blog space. 

Unified Security Operations Platform: Microsoft Defender XDR & Microsoft Sentinel

  • From on-premises to cloud: Graph-powered detection of hybrid attacks with Microsoft exposure graph. In this blog, we explain how the exposure graph, an integral part of our pre-breach security exposure solution, supercharges our post-breach threat protection capabilities to detect and respond to such multi-faceted threats. 
  • (Public Preview) Unified detections rules list that includes both analytics rules and custom detections is in public preview. Learn more in our docs.
  • The Best of Microsoft Sentinel — Now in Microsoft Defender. We are proud to share that the most advanced and integrated SIEM experience from Microsoft Sentinel is now fully available within the Microsoft Defender portal as one unified experience. 
  • (General Available) Multi workspace for single and multi tenant is now in General Available.
  • (Public Preview) Case management now available for the Defender multitenant portal. For more information, see View and manage cases across multiple tenants in the Microsoft Defender multitenant portal.
  • (Public Preview) You can now highlight your security operations achievements and the impact of Microsoft Defender using the unified security summary. For more information, see Visualize security impact with the unified security summary.
  • (Public Preview) New Microsoft Teams table: The MessageEvents table contains details about messages sent and received within your organization at the time of delivery
  • (Public Preview) New Microsoft Teams table: The MessagePostDeliveryEvents table contains information about security events that occurred after the delivery of a Microsoft Teams message in your organization
  • (Public Preview) New Microsoft Teams table: The MessageUrlInfo table contains information about URLs sent through Microsoft Teams messages in your organization
  • Unified IdentityInfo table in advanced hunting now includes the largest possible set of fields common to both Defender and Azure portals.

Microsoft Defender for Endpoint

Microsoft Defender for Office 365

Microsoft Defender for Cloud Apps

  • New Applications inventory page now available in Defender XDR. The new Applications page in Microsoft Defender XDR provides a unified inventory of all SaaS and connected OAuth applications across your environment. For more information, see Application inventory overview.
  • The Cloud app catalog page has been revamped to meet security standards. The new design includes improved navigation, making it easier for you to discover and manage your cloud applications.
  • Note: As part of our ongoing convergence process across Defender workloads, Defender for Cloud Apps SIEM agents will be deprecated starting November 2025. Learn more.

Microsoft Defender for Identity

  • (Public Preview) Expanded New Sensor Deployment Support for Domain Controllers. Learn more.
  • Active Directory Service Accounts Discovery Dashboard. Learn more
  • Improved Visibility into Defender for Identity New Sensor Eligibility in the Activation page. The Activation Page now displays all servers from your device inventory, including those not currently eligible for the new Defender for Identity sensor.
  • Note: Local administrators collection (using SAM-R queries) feature will be disabled. 

Microsoft Security Blogs

Threat Analytics (Access to the Defender Portal needed)

Updated Jun 05, 2025
Version 2.0
No CommentsBe the first to comment