Modern Work Weekly - Week of 2026-08-04
Defender for Office 365 Plan 1 lands in M365 E3, Writeback for Cloud-Managed Remote Mailboxes hits GA, and Midnight Blizzard is actively targeting hospitality sign-in portals - a rich week of capability unlocks alongside real threat intelligence to act on.
Top 5
Defender for Office 365 Plan 1 now included in Microsoft 365 E3 - If your organization is on E3, you just gained anti-phishing, safe links, safe attachments, and real-time detections without an additional license purchase. Audit what you were paying for separately and update your security baseline accordingly.
Writeback for Cloud-Managed Remote Mailboxes hits GA - The critical milestone for retiring your last on-premises Exchange server is here. Writeback is live in WW, GCCH, DoD, and 21Vianet, supporting up to 600,000 cloud-managed mailboxes per tenant. If you have been waiting on this to pull the plug on your last Exchange box, the blocker is gone.
CaptiveCrunch: Midnight Blizzard actively targeting hospitality sign-in portals - Storm-2945 has been compromising hotel and hospitality sign-in portals since May 2026 to deliver malware and steal credentials from travelers. If your users travel frequently or your org is in the hospitality sector, review your conditional access policies and endpoint posture for travel scenarios now.
Unified RBAC is now the default for new Defender for Office 365 Plan 2 orgs - Starting July 2026, any new MDO Plan 2 tenant lands on Microsoft Defender Unified RBAC by default. Existing tenants are not automatically migrated, but this is the direction of travel: review MC1246006 and plan your RBAC migration if you are still on the legacy model.
Domain Exclusion for Microsoft 365 Copilot is GA - Admins can now explicitly block specific external domains from being used as web grounding sources in Copilot responses. This is a meaningful compliance and data governance control for organizations in regulated industries or with strict trusted-source policies.
Identity & Access
Give Every AI Agent Its Own Identity [GA] - Microsoft Entra Agent ID provides each AI agent a unique, managed identity so you can apply visibility, governance, and Zero Trust controls to non-human actors the same way you do for users. Agents with broad permissions are a high-value target: a misconfigured or compromised agent can traverse your environment at machine speed. Start inventorying agents in your tenant and assigning least-privilege identities through Entra Agent ID.
Writeback for Cloud-Managed Remote Mailboxes: Now Generally Available [GA] - Writeback allows Exchange Online to hold the Source of Authority for Exchange attributes on directory-synced mailboxes, eliminating the last dependency that keeps many orgs tethered to on-premises Exchange. Available now in WW, GCCH, DoD, and 21Vianet for up to 600,000 mailboxes per tenant. If retiring your last Exchange server is on the roadmap, this is the GA signal to move that project off hold.
Microsoft Teams: View and manage auto attendant shared voicemails directly in the Queues app [GA] - Auto Attendant calls routed to voicemail will now surface directly in the Queues app, giving contact center and telephony teams a centralized place to track and respond. Targeting August 2026 GA; validate that your Queues app deployment and Auto Attendant routing configurations are in place before rollout.
Endpoint & Device Management
- What’s new in Microsoft Intune - July [GA] - This month’s Intune release centers on visibility and troubleshooting confidence, headlined by improved Windows device sync status surfacing so admins can diagnose sync issues faster without guesswork. Review the full July changelog and cross-reference against your current compliance and configuration policies to catch any behavioral changes before they hit your fleet.
Collaboration & Productivity
What’s New in Microsoft Teams | April 2026 [GA] - The April Teams roundup covers AI-enhanced collaboration, calling improvements, and hybrid meeting enhancements from M365 Community Conference. If your team did not review this at release, cross-check the feature list against your Teams policies and governance controls.
From AI Experiments to Digital Workforce: Do Enterprises Need a Chief Agent Officer? [GA] - As agent fleets grow, ownership is fragmenting across IT, security, and compliance with no clear accountability model. This piece frames the governance gap around AI agents that can access enterprise data, invoke tools, and act autonomously. Use this as a conversation-starter with leadership about establishing a formal agent governance model before the sprawl becomes unmanageable.
Writeback for Cloud-Managed Remote Mailboxes: Now in Public Preview [Preview] - Note: this item has since reached GA (see Identity & Access section). The public preview post remains useful context for the full writeback journey and community feedback that shaped the GA release.
What’s New in Microsoft 365 Copilot | July 2026 [GA] - July’s Copilot update delivers agent additions in Copilot Chat, model updates in the Copilot app and Cowork, expanded reference support in Copilot Notebooks, new Word skills, and Power Platform integrations. Review the full feature list against your Copilot deployment and ensure users are aware of new capabilities relevant to their workflows.
What’s New in Microsoft Teams | July 2026 [GA] - July Teams highlights include the new Meeting Recaps app for finding and catching up on past meetings, and improved app and agent management controls for IT. Review the Meeting Recaps app rollout timeline and update your Teams app governance policies to account for the new agent management capabilities.
What’s new in Microsoft Security: July 2026 [GA] - The July security roundup covers AI environment security, AI-assisted defense tooling, and foundational hardening for AI-powered operations. Worth a read for security and IT leads to align on which new capabilities are relevant to your current roadmap.
Localized default Mark as and notify email templates [GA] - When using the default admin notification template for user-reported messages, users now receive emails in their Outlook preferred language automatically. Custom admin-configured templates are not affected, so no action is required if you have customized these templates already.
Unified RBAC is the default permission model for new Defender for Office 365 Plan 2 organizations [GA] - Starting July 2026, new MDO Plan 2 tenants land on Unified RBAC by default. Existing orgs are not auto-migrated, but this is the long-term direction: review MC1246006, assess your current RBAC model, and plan migration to avoid being on a legacy permission model as feature development focuses on Unified RBAC.
Microsoft Defender for Office 365 Plan 1 included in Microsoft 365 E3 [GA] - MDO Plan 1 is now bundled into M365 E3 at no additional cost. Check whether your E3 users are currently covered by a separate MDO Plan 1 license purchase, and reconcile your license spend accordingly. Confirm that the Plan 1 capabilities are active and properly configured for your E3 user population.
Prompt injection protection [GA] - Defender for Office 365 now detects prompt injection attacks hidden in inbound email, an increasingly relevant threat as employees use email-connected AI tools. Verify this detection capability is enabled in your anti-phishing and email threat policies and confirm your SOC knows what alert signals to expect.
SharePoint Showcase: 10 Custom AI Skills Every SharePoint Site Owner Should Build [GA] - Copilot skills in SharePoint let teams define reusable natural-language instructions for recurring tasks like summarizing meetings, generating reports, and reviewing documents, persisted at the site level. If you are rolling out Copilot for Microsoft 365, this is a practical guide to help site owners drive consistent, high-quality AI usage within their teams.
Dataverse Plugin for Coding Agents: OpenAI and Codex Marketplace Expansion [GA] - The Dataverse plugin is now available in the OpenAI and Codex agent marketplaces, extending Dataverse connectivity to developers working outside the Microsoft toolchain. Assess whether this opens new data access paths that require governance or DLP policy updates in your environment.
Microsoft Teams: See more messages on mobile [GA] - A streamlined mobile messaging layout will display more content on screen with improved readability, targeting September 2026 GA. No admin action required, but surface this to your Teams champions so users are not surprised by the layout change.
Microsoft Teams: Updated header and dashboard for chats and channels on mobile [GA] - A redesigned channel header and lightweight dashboard on Teams mobile brings channel details, people, and pinned content into a single view, aligning mobile and desktop experiences more closely. Targeting September 2026 GA; communicate the change to end users ahead of rollout to reduce support tickets.
Microsoft Teams: Clearer text highlighting in dark mode [GA] - Highlighted text rendering in dark mode composition has been improved for consistency. Targeting September 2026 GA; no admin action required.
Microsoft Teams: Teams shared display mode and peripheral detection available for DoD environments [GA] - Shared display mode for private meeting hosting from a PC and BYOD peripheral detection for the Pro Management portal are now available in Teams for DoD, targeting August 2026 GA. DoD admins should validate their Pro Management portal configuration and confirm peripheral inventory reporting is working as expected.
Microsoft Teams: Ability for IT admins to customize user notification messages for recording and transcription in calls [GA] - Admins will be able to customize the user-facing notification message text for recording and transcription during Teams calls, targeting August 2026 GA. Prepare your custom notification language now, especially if your organization has legal or compliance requirements around recording disclosures.
Microsoft Teams: Enhanced delegated calling with delegate call access restrictions and join notifications [GA] - Delegators can now lock an active call to prevent delegates from joining or resuming it, and can enable warning tones when a delegate joins. Targeting August 2026 GA; brief your telephony admins and delegator user group on the new controls, particularly in executive assistant and legal scenarios where call privacy matters.
Planner: Task Details Side Pane experience [GA] - Task details now open in a side pane rather than a modal dialog, keeping your Board, Grid, or My Tasks view visible while editing. This was targeted for July 2026 GA and should already be rolling out; no admin action required.
SharePoint: Admin Center detailed report on Everyone except external user permissions [GA] - SharePoint Advanced Management admins now get an item-level permissions report covering the “Everyone except external users” and “Everyone” special groups, targeting August 2026 GA. If broad-access permissions are a compliance concern in your tenant, prioritize reviewing this report once it lands and remediate overshared content.
AI & Copilot
Why Ungoverned AI Agents Are Dangerous [GA] - AI semantic search can surface previously hard-to-find data, and agents with broad permissions can move through an organization at speeds that make manual detection ineffective. This is a useful framing resource for security awareness conversations with stakeholders who underestimate agent risk.
The next measure of AI momentum is work transformed [GA] - Microsoft 365 Copilot has surpassed 30 million paid seats with net seat adds more than doubling quarter over quarter. Adoption at this scale means your users are likely encountering Copilot in more contexts: make sure your data governance and sensitivity labeling posture is solid before broader rollout compounds any existing oversharing issues.
Prompt Columns in GA: Turning Business Apps Data into Persisted AI Insights [GA] - Power Platform Prompt Columns allow natural-language prompts to be embedded directly in Dataverse tables, with AI-generated outputs persisted in the data. Evaluate whether Prompt Columns need to be governed under your existing AI and data classification policies, particularly for tables containing sensitive business data.
Microsoft Viva: Viva Glint - Copilot admin configuration assistance [GA] - A Copilot-powered conversational assistant embedded in the Viva Glint admin experience will answer configuration and how-to questions with deep links to settings pages, targeting September 2026 GA. Available only to Glint users with Admin permissions; no broader data access concerns, but confirm it is on your radar if you manage Glint.
Security & Compliance
Secure by default: Trusted Launch as Default is now Generally Available [GA] - New Azure Gen2 VMs and VM scale sets now deploy with Secure Boot and vTPM enabled by default at no extra cost, raising your baseline without any per-VM configuration. If you use ARM templates, Bicep, Terraform, or SDKs for deployments, a one-time registration is required to enable TLaD for those tooling paths; Portal, PowerShell, and CLI already default to it.
Why AI Agents May Require a New Security Operations Model [GA] - A compromised AI agent can exfiltrate data, invoke tools, interact with other agents, and execute actions at machine speed, combining the blast radius of a compromised endpoint and a compromised identity simultaneously. This post makes the case that existing SOC models are not designed for this threat surface. Share with your security leadership to drive the conversation on agent-specific detection and response playbooks.
CVE-2026-50416 Win32k Information Disclosure Vulnerability [GA] - Acknowledgment updated; verify this CVE is covered in your current patch cycle and confirm affected systems are patched.
CVE-2026-50341 Windows NTFS Information Disclosure Vulnerability [GA] - Acknowledgment updated; confirm NTFS-related patches are applied across your Windows fleet, particularly for devices handling sensitive file shares.
CVE-2026-50493 DirectX Graphics Kernel Elevation of Privilege Vulnerability [GA] - Acknowledgment updated; EoP vulnerabilities in the graphics kernel are high-priority on shared or multi-user systems. Confirm patch status.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft [GA] - Storm-2945, a Midnight Blizzard sub-cluster, has been compromising hotel and hospitality sign-in portals since May 2026 to deliver malware and steal credentials from travelers. Review conditional access policies for travel scenarios, enforce device compliance before granting access from unknown networks, and ensure your threat hunting queries are looking for indicators tied to this campaign.
CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability [GA] - Acknowledgment updated; RCE in the DHCP client is a critical-class risk on any networked Windows device. Validate patching across your fleet.
CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability [GA] - Acknowledgment updated; RCE via Office is a perennial high-priority. Confirm Office update channels are current and macro/document protection policies are enforced.
CVE-2026-56197 Windows Admin Center Remote Code Execution Vulnerability [GA] - Acknowledgment updated; WAC is often deployed on management servers with broad network access, making RCE here especially impactful. Patch and review WAC network exposure.
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability [GA] - Improper access control in Azure Cosmos DB allows an unauthenticated network attacker to execute code. If you run Cosmos DB workloads, confirm your instances are patched and review network access controls to limit exposure.
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability [GA] - Informational update only; confirm this CVE is on your remediation tracking list and that ARM-related patches are applied in your Azure environment.
The Microsoft AI and Agent Platform - The Platform Behind Intelligent Agents [GA] - This post frames how Microsoft’s agent platform handles enterprise governance, trust, and scale, positioning the infrastructure around the model as the real differentiator. Useful background for architects evaluating how Microsoft’s agent governance capabilities map to your organization’s requirements.
Better security starts with better questions [GA] - A strategic perspective on using AI-assisted questioning and human judgment to improve security decision-making. Worth sharing with security leadership for the framing on building resilient, AI-informed security practices.
Assign a CVE to GitHub Copilot, Get a Pull Request [GA] - The Defender for Cloud to GitHub Copilot coding agent integration lets you go from a container CVE recommendation to a draft pull request without leaving the workflow. If your team manages containerized workloads, evaluate whether this loop can accelerate your vulnerability remediation SLA.
This Policy Blocked an Image With 415 CVEs [GA] - Defender for Cloud security policies can deny deployment of non-compliant container images at the namespace level, blocking supply chain risk at the gate. If you run Kubernetes workloads, validate that you have namespace-scoped image policies in place and test them against your current image baseline.
Chromium: CVE-2026-13032 Use after free in WebGL [GA] - Chrome-assigned CVE addressed in Chromium-based Edge. Ensure Edge is current on all managed endpoints.
Chromium: CVE-2026-13030 Uninitialized Use in GPU [GA] - Chrome-assigned CVE addressed in Chromium-based Edge. Ensure Edge is current on all managed endpoints.
Chromium: CVE-2026-13028 Use after free in WebGL [GA] - Chrome-assigned CVE addressed in Chromium-based Edge. Two WebGL use-after-free vulnerabilities in the same release cycle is worth noting for environments with heavy browser-based workloads. Prioritize Edge updates accordingly.
More control over web grounding with Domain Exclusion for Microsoft 365 Copilot [GA] - Admins can now explicitly exclude specific external domains from being used as web grounding sources in Copilot and Copilot Chat responses. This is a direct compliance control: define your excluded domain list now, particularly if your organization operates under data residency, regulatory, or trusted-source policies.
Action Required
CaptiveCrunch threat campaign (active, ongoing): Storm-2945 / Midnight Blizzard has been actively compromising hospitality sign-in portals since May 2026. Review the campaign details and update conditional access policies for travel and untrusted network scenarios. Ensure your threat hunting rules cover indicators from this campaign. If your org is in the hospitality sector, treat your sign-in infrastructure as actively targeted.
Trusted Launch as Default - one-time registration required for IaC tooling: TLaD is GA and active for Portal, PowerShell, and CLI, but ARM templates, Bicep, Terraform, and SDK-based deployments require a one-time opt-in registration. Complete this registration now to avoid deploying Gen2 VMs without Secure Boot and vTPM from your automation pipelines.
MDO Plan 1 now included in M365 E3 - reconcile licensing: Microsoft Defender for Office 365 Plan 1 is now bundled in M365 E3. If you purchased MDO Plan 1 as an add-on for E3 users, audit your license inventory and remove redundant add-on licenses to recover spend. Also confirm that MDO Plan 1 capabilities are properly activated for your E3 population.
SharePoint Advanced Management - “Everyone except external users” permissions report (August 2026): The new item-level permissions report targeting August GA will expose exactly which content has been shared broadly via the “Everyone except external users” and “Everyone” groups. Assign an owner now to review and act on findings at launch; broad-access permissions are a common compliance finding and this report removes the audit gap.
Unified RBAC for Defender for Office 365 Plan 2 - migration planning: New orgs default to Unified RBAC from July 2026. Existing orgs are not auto-migrated, but MDO feature investment is tracking toward Unified RBAC. Review MC1246006, configure Unified RBAC for MDO, and schedule your migration before legacy model support erodes.
Teams call recording/transcription notification customization (August 2026): Admin-customizable notification messages for recording and transcription disclosures are GA in August. If your organization has legal or compliance requirements around how recording consent is communicated, draft and test your custom notification text before the feature lands.
Documentation Updates
Identity & Access
SMS/voice MFA retirement: dedicated FAQ page published - The SMS and voice call MFA retirement FAQ has been split into its own dedicated page, making it easier to locate answers on the retirement timeline, user impact, and migration steps.
New Zscaler ZIdentity integration tutorial added - A new step-by-step tutorial covers configuring the Zscaler ZIdentity integration with Microsoft Entra ID, relevant for organizations running Zscaler in their network stack alongside Entra-managed identities.
Global Secure Access: guidance for remote network CPE behind NAT - New guidance documents how to configure remote network Customer Premises Equipment (CPE) when it sits behind NAT, addressing a deployment scenario that was previously underdocumented for Global Secure Access.
Global Secure Access: revised Internet Access profile documentation - The Internet Access profile docs have been substantially revised; if you are configuring or auditing Global Secure Access Internet Access policies, review the updated guidance for changed prerequisites or procedures.
New reference article: custom call-outs for Entra attribute mappings - A new reference article documents custom call-outs as an extensibility mechanism for Entra attribute mappings, covering API instructions and configuration details for provisioning engineers.
New multitenant architecture guide published - A new architectural guidance document covers multitenant Entra ID design patterns, authored by recognized Entra architects. Relevant for any organization managing or designing for multiple Entra tenants.
Endpoint & Device Management
Microsoft Tunnel: updated prerequisites documentation - Prerequisites for Microsoft Tunnel have been updated; review before any new Tunnel deployments or upgrades to avoid configuration failures.
Configuration Manager: CVE-2026-47301 referenced in console extension fix KB - The KB article for the Configuration Manager console extension fix now explicitly references CVE-2026-47301, clarifying that this update addresses the specific vulnerability. Confirm this KB is applied in your ConfigMgr environment.
Configuration Manager KB38232642: CVE-2026-47301 reference added - A second Configuration Manager KB now also explicitly calls out CVE-2026-47301 coverage, ensuring the vulnerability is traceable across both relevant KB articles.
Security & Compliance
Tenant Allow/Block List: updated block entry behavior for domains and subdomains - The explanation of how block entries apply to domains versus subdomains in the Tenant Allow/Block List has been corrected or clarified; review if you manage block entries and need accurate scoping behavior documented.
Tenant Allow/Block List: general article updates - The main Tenant Allow/Block List reference article received substantive updates alongside the domain/subdomain block entry clarification; worth a re-read if this is part of your active MDO configuration.
IIJ added as a trusted ARC sealer in Defender for Office 365 guidance - IIJ (Internet Initiative Japan) has been added to the documented list of trusted ARC sealers for Defender for Office 365 configurations. Relevant if your mail flow routes through IIJ and you are configuring ARC trusted sealers for anti-spoofing accuracy.
Sources
- https://techcommunity.microsoft.com/t5/microsoft-security-community/secure-by-default-trusted-launch-as-default-is-now-generally/ba-p/4541672
- https://techcommunity.microsoft.com/t5/microsoft-security-community/why-ai-agents-may-require-a-new-security-operations-model/ba-p/4542532
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50416
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50341
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50493
- https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
- https://www.youtube.com/shorts/Lf2KEXY1WEg
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54128
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55129
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56197
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66803
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24304
- https://techcommunity.microsoft.com/t5/microsoft-security-community/the-microsoft-ai-and-agent-platform-the-platform-behind/ba-p/4539060
- https://www.microsoft.com/en-us/security/blog/2026/07/29/better-security-starts-with-better-questions/
- https://www.youtube.com/shorts/Q7BQG2_WDzY
- https://www.youtube.com/shorts/hYI3T0UnXKg
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13032
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13030
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13028
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/more-control-over-web-grounding-with-domain-exclusion-for/ba-p/4540151
- https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-july/ba-p/4537392
- https://techcommunity.microsoft.com/t5/microsoft-teams-blog/what-s-new-in-microsoft-teams-april-2026/ba-p/4515907
- https://techcommunity.microsoft.com/t5/microsoft-security-community/from-ai-experiments-to-digital-workforce-do-enterprises-need-a/ba-p/4542520
- https://techcommunity.microsoft.com/t5/exchange-team-blog/writeback-for-cloud-managed-remote-mailboxes-now-in-public/ba-p/4520138
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/what-s-new-in-microsoft-365-copilot-july-2026/ba-p/4538332
- https://techcommunity.microsoft.com/t5/microsoft-teams-blog/what-s-new-in-microsoft-teams-july-2026/ba-p/4542510
- https://www.microsoft.com/en-us/security/blog/2026/07/30/whats-new-in-microsoft-security-july-2026/
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/sharepoint-showcase-10-custom-ai-skills-every-sharepoint-site/ba-p/4535414
- https://www.microsoft.com/en-us/power-platform/blog/2026/07/28/dataverse-plugin-for-coding-agents-openai-and-codex-marketplace-expansion/
- https://www.microsoft.com/microsoft-365/roadmap?id=568067
- https://www.microsoft.com/microsoft-365/roadmap?id=567461
- https://www.microsoft.com/microsoft-365/roadmap?id=566858
- https://www.microsoft.com/microsoft-365/roadmap?id=567465
- https://www.microsoft.com/microsoft-365/roadmap?id=567302
- https://www.microsoft.com/microsoft-365/roadmap?id=567306
- https://www.microsoft.com/microsoft-365/roadmap?id=566866
- https://www.microsoft.com/microsoft-365/roadmap?id=561038
- https://www.youtube.com/shorts/j8AGpZ8Z2yA
- https://techcommunity.microsoft.com/t5/exchange-team-blog/writeback-for-cloud-managed-remote-mailboxes-now-generally/ba-p/4543507
- https://www.microsoft.com/microsoft-365/roadmap?id=567457
- https://www.youtube.com/shorts/XdgO2fjg3KQ
- https://www.microsoft.com/en-us/microsoft-365/blog/2026/07/30/the-next-measure-of-ai-momentum-is-work-transformed/
- https://www.microsoft.com/en-us/power-platform/blog/2026/07/29/prompt-columns-july2026/
- https://www.microsoft.com/microsoft-365/roadmap?id=567320
- https://github.com/MicrosoftDocs/entra-docs/commit/938217238eb9520112ac2f6eafad1eac6c1b78d6
- https://github.com/MicrosoftDocs/entra-docs/commit/0372550fa2b9824e825d48440331bd42e9ac880c
- https://github.com/MicrosoftDocs/entra-docs/commit/649f7a17c18170104e4cf9aae8c93ffac9fcf00f
- https://github.com/MicrosoftDocs/entra-docs/commit/73565b59f03b2578d8099cbc0d8525cccf829532
- https://github.com/MicrosoftDocs/entra-docs/commit/3824f4a3001ebf731808b7c8ce205f1149838c39
- https://github.com/MicrosoftDocs/entra-docs/commit/7eb64a786de183ec4cb0483b41187ac879813984
- https://github.com/MicrosoftDocs/memdocs/commit/52b93b3a20cbcecd14913f209523bdf63ad7eb8c
- https://github.com/MicrosoftDocs/memdocs/commit/6d50432a73a4967dc4acd5a400630bec719b552e
- https://github.com/MicrosoftDocs/memdocs/commit/cbe3720f68b54cb13508bb5e72779c95cd0e783f
- https://github.com/MicrosoftDocs/defender-docs/commit/3e913ef1187a6ea001eb6df467970a007da91eb5
- https://github.com/MicrosoftDocs/defender-docs/commit/b225a9a99200cb15b8e1ba1a58c3b6ef0b8e2bbf
- https://github.com/MicrosoftDocs/defender-docs/commit/ba8a948070bbe3dd56f8d6211b7df43f9a8bcaaa
