Monitoring

Pinned post

New Microsoft Sentinel features: Multi-account connectors and UEBA updates

AI playbook generator in Defender portal (image Microsoft)

Microsoft Sentinel, Microsoft’s cloud-based SIEM (Security Information and Event Management) platform, received several updates in August 2026. The most practical change for many administrators is multi-account support for Auth0, CrowdStrike Falcon, and Salesforce Service Cloud data connectors, now generally available. Microsoft also expanded User and Entity Behavior Analytics (UEBA) anomaly detection and completed the convergence of Microsoft Defender Threat Intelligence (MDTI) into a free connector.

New Microsoft Sentinel features: Multi-account connectors and UEBA updates More...

An infostealer log can bypass MFA—respond within the first hour

An infostealer log can bypass MFA—respond within the first hour

A corporate password found in an infostealer log should be treated as a possible live identity compromise, not just an old credential leak. Security teams need to determine within minutes whether the data includes active browser sessions, identity-provider access, VPN or RDP credentials, and then revoke sessions and reset passwords before attackers can use them.

An infostealer log can bypass MFA—respond within the first hour More...

CISA’s Logging Reference Architecture gives every security team a testing plan

CISA’s Logging Reference Architecture gives every security team a testing plan

CISA’s new Logging Reference Architecture is aimed at federal agencies, but its practical value extends to critical-infrastructure operators and state, local, territorial, and tribal governments. The guidance provides checklists that organizations can use to test whether their logs are timely, detailed, protected, and useful during both active attacks and forensic investigations.

CISA’s Logging Reference Architecture gives every security team a testing plan More...

Monitor GPU and NPU workloads in Windows Task Manager

Task Manager NPU performance graph (image Microsoft)

Windows 11 Task Manager can show per-process NPU and GPU neural engine usage, helping you determine whether an AI app runs on dedicated AI hardware or falls back to the CPU. Microsoft introduced the optional columns in updates KB5089573 and KB5094126 for Windows 11 versions 24H2 and 25H2. Availability remains a gradual rollout on eligible devices.

Monitor GPU and NPU workloads in Windows Task Manager More...

Microsoft Sentinel UEBA anomalies on the behaviors layer

UEBA behaviors layer data flow (image Microsoft)

Microsoft Sentinel now attaches User and Entity Behavior Analytics (UEBA) insights to records from the UEBA behaviors layer. UEBA is a machine-learning feature that builds a baseline of typical activity for users, hosts, IP addresses, and applications, then flags activity that does not match that baseline. The behaviors layer groups raw security logs into structured summaries of who did what to whom. Microsoft added those findings to each behavior and expanded UEBA coverage to selected firewall, proxy, and cloud sources. The anomalies-on-behaviors capability is in preview and is available only for Microsoft Sentinel in the Microsoft Defender portal.

Microsoft Sentinel UEBA anomalies on the behaviors layer More...

Microsoft retires standalone MDTI, integrates threat intelligence into Defender XDR and Sentinel

MDTI capabilities across Defender and Sentinel (image Microsoft)

Microsoft retired the standalone Microsoft Defender Threat Intelligence (MDTI) experience on August 1, 2026. Its threat intelligence capabilities now appear in the Microsoft Defender portal for Microsoft Defender XDR and Microsoft Sentinel. For administrators, this is mainly a portal and licensing change, but verify where your security team accesses intelligence before removing an existing MDTI subscription.

Microsoft retires standalone MDTI, integrates threat intelligence into Defender XDR and Sentinel More...

Cloudflare Identity-Aware AI Gateway puts names behind AI requests

Cloudflare Identity-Aware AI Gateway puts names behind AI requests

Cloudflare’s Identity-Aware AI Gateway now lets enterprises connect AI requests to verified employees, devices, and automated systems instead of anonymous shared API keys. The service combines identity-aware access with spending controls, anomaly detection, logging, and safeguards for prompts sent to external AI providers.

Cloudflare Identity-Aware AI Gateway puts names behind AI requests More...

WindowsUpdatePreventer
Scroll to Top