Skip to content

Commit 659b7fa

Browse files
authored
Merge branch 'main' into urbac-mto-ga
2 parents 38a541a + 47cce50 commit 659b7fa

File tree

42 files changed

+283
-223
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

42 files changed

+283
-223
lines changed

.openpublishing.publish.config.json

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -191,6 +191,8 @@
191191
".openpublishing.redirection.defender-cloud-apps.json",
192192
".openpublishing.redirection.defender-endpoint.json",
193193
".openpublishing.redirection.defender-office-365.json",
194-
".openpublishing.redirection.defender-xdr.json"
194+
".openpublishing.redirection.defender-xdr.json",
195+
".openpublishing.redirection.unified-secops.json"
196+
195197
]
196198
}
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
{
2+
"redirections": [
3+
{
4+
"source_path": "unified-secops-platform/mto-tenantgroups.md",
5+
"redirect_url": "mto-distribution-profiles",
6+
"redirect_document_id": false
7+
}
8+
]
9+
}

defender-endpoint/microsoft-defender-antivirus-updates.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -99,6 +99,30 @@ Updates contain:
9999
- Serviceability improvements
100100
- Integration improvements (Cloud, [Microsoft Defender XDR](/defender-xdr/microsoft-365-defender))
101101

102+
103+
### July-2025 (Platform: 4.18.25070.5 | Engine: 1.1.25070.4)
104+
105+
- Security intelligence update version: **1.435.11.0**
106+
- Release date: **August 5, 2025 (Engine) / August 6, 2025 (Platform)**
107+
- Platform: **4.18.25070.5**
108+
- Engine: **1.1.25070.4**
109+
- Support phase: **Security and Critical Updates**
110+
111+
#### What's new
112+
113+
- Enhanced Passive Mode Scanning Behavior
114+
When Microsoft Defender is in Passive mode, an Antivirus scan will not occur after a signature update , unless specifically set in the policy setting DisableScanOnUpdate.
115+
116+
- Improved Tamper Protection Handling
117+
Optimized the configuration process for Tamper Protection in multi-threaded environments to ensure more reliable behavior.
118+
119+
- Digital Signature Verification Performance Boost
120+
Enhanced the efficiency of digital signature verification to improve overall system performance.
121+
122+
- Refined ASR Rule Exclusion Processing
123+
Refined exclusion processing and resolved false positives for the Attack Surface Reduction (ASR) rule: Block Office applications from injecting code into other processes.
124+
125+
102126
### June-2025 (Platform: 4.18.25060.7 | Engine: 1.1.25060.6)
103127

104128
- Security intelligence update version: **1.433.2.0**

defender-office-365/air-view-investigation-results.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -349,7 +349,7 @@ On the investigation details page, the **Entities** tab shows details about the
349349

350350
The **Entities** tab is organized by a view selection pane (a summary view and a view for each entity type) and a corresponding details table for that view:
351351

352-
- **Evidence summary** view: This is the default view.
352+
- **Evidence summary** view: This view is the default.
353353

354354
You can sort the entries in the details table by clicking on an available column header. Select :::image type="icon" source="media/m365-cc-sc-customize-icon.png" border="false"::: **Customize columns** to change the columns that are shown. By default, all available columns are selected:
355355

defender-office-365/anti-phishing-policies-mdo-configure.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -112,7 +112,7 @@ For anti-phishing policy procedures in organizations without Defender for Office
112112
5. On the **Phishing threshold & protection** page, configure the following settings:
113113

114114
- **Phishing email threshold**: Use the slider to select one of the following values:
115-
- **1 - Standard** (This is the default value.)
115+
- **1 - Standard** (This value is the default.)
116116
- **2 - Aggressive**
117117
- **3 - More aggressive**
118118
- **4 - Most aggressive**

defender-office-365/anti-spam-policies-asf-settings-about.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ For each ASF setting, the following options are available in anti-spam policies:
5252
- **On**: ASF adds the corresponding X-header field to the message:
5353
- For [Increase spam score settings](#increase-spam-score-settings), the message has a higher chance of being marked as**Spam**.
5454
- For [Mark as spam settings](#mark-as-spam-settings), the message is marked as **Spam** or **High confidence spam**.
55-
- **Off**: The ASF setting is disabled. This is the default value.
55+
- **Off**: The ASF setting is disabled. This value is the default.
5656
- **Test**: The ASF setting is in Test Mode. What happens to the message is determined by the **Test mode** (_TestModeAction_) value:
5757
- **None**: Message delivery is unaffected by the ASF detection. The message is still subject to other types of filtering and rules.
5858
- **Add default X-header text** (_AddXHeader_): The X-header value `X-CustomSpam: This message was filtered by the custom spam filter option` is added to the message. You can use this value in Inbox rules (not mail flow rules) to affect the delivery of the message.

defender-office-365/attack-simulation-training-end-user-notifications.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,7 @@ On the details flyout from the **Tenant notifications** tab only, select **Edit
111111
- **From display name**: Enter the display name of the sender.
112112
- **From email address**: Enter the email address of the sender.
113113
- **Select the language of the email**: Select one of the following languages: **Chinese (Simplified)**, **Chinese (Traditional, Taiwan)**, **English**, **French**, **German**, **Italian**, **Japanese**, **Korean**, **Portuguese**, **Russian**, **Spanish**, **Dutch**, **Polish**, **Arabic**, **Finnish**, **Greek**, **Hungarian**, **Indonesian**, **Norwegian Bokmål**, **Romanian**, **Slovak**, **Swedish**, **Thai**, **Turkish**, **Vietnamese**, **Catalan**, **Croatian**, or **Slovenian**.
114-
- **Mark this as the default language**: Because this is the first and only language for the notification, this language value is selected as the default, and you can't change it.
114+
- **Mark this as the default language**: Because this language is the first and only language for the notification, this language value is selected as the default, and you can't change it.
115115
- **Subject**: The default that's used depends on the notification type that you selected in the previous step, but you can change it:
116116
- Positive reinforcement: **Thank you for reporting a phish!**
117117
- Simulation: **Thank you for participating in a phishing campaign!**

defender-office-365/attack-simulation-training-simulation-automations.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -276,12 +276,12 @@ Use the following options on the page to assign trainings as part of the simulat
276276

277277
- **Preferences** section: In **Select training content preference**, choose one of the following options in the dropdown list:
278278

279-
- **Microsoft training experience (Recommended)**: This is the default value. This value has the following associated options to configure on the page:
279+
- **Microsoft training experience (Recommended)**: This value is the default. This value has the following associated options to configure on the page:
280280
- Select one of the following values:
281-
- **Assign training for me (Recommended)**: This is the default value. We assign training based on a user's previous simulation and training results.
281+
- **Assign training for me (Recommended)**: This value is the default. We assign training based on a user's previous simulation and training results.
282282
- **Select training courses and modules myself**: If you select this value, the next step in the wizard is **Training assignment** where you find and select trainings. The steps are described in the [Training assignment](#training-assignment) subsection.
283283
- **Due date** section: In **Select a training due date**, choose one of the following values:
284-
- **30 days after simulation ends** (this is the default value)
284+
- **30 days after simulation ends** (this value is the default)
285285
- **15 days after simulation ends**
286286
- **7 days after simulation ends**
287287

@@ -291,7 +291,7 @@ Use the following options on the page to assign trainings as part of the simulat
291291
- **Custom training description**
292292
- **Custom training duration (in minutes)**: The default value is 0, which means there's no specified duration for the training.
293293
- **Due date** section: In **Select a training due date**, choose one of the following values:
294-
- **30 days after simulation ends** (this is the default value)
294+
- **30 days after simulation ends** (this value is the default)
295295
- **15 days after simulation ends**
296296
- **7 days after simulation ends**
297297

defender-office-365/attack-simulation-training-simulations.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -303,12 +303,12 @@ Use the following options on the page to assign trainings as part of the simulat
303303

304304
- **Preferences** section: In **Select training content preference**, choose one of the following options in the dropdown list:
305305

306-
- **Microsoft training experience (Recommended)**: This is the default value. This value has the following associated options to configure on the page:
306+
- **Microsoft training experience (Recommended)**: This value is the default. This value has the following associated options to configure on the page:
307307
- Select one of the following values:
308-
- **Assign training for me (Recommended)**: This is the default value. We assign training based on a user's previous simulation and training results.
308+
- **Assign training for me (Recommended)**: This value is the default. We assign training based on a user's previous simulation and training results.
309309
- **Select training courses and modules myself**: If you select this value, the next step in the wizard is **Training assignment** where you find and select trainings. The steps are described in the [Training assignment](#training-assignment) subsection.
310310
- **Due date** section: In **Select a training due date**, choose one of the following values:
311-
- **30 days after simulation ends** (this is the default value)
311+
- **30 days after simulation ends** (this value is the default)
312312
- **15 days after simulation ends**
313313
- **7 days after simulation ends**
314314

@@ -318,7 +318,7 @@ Use the following options on the page to assign trainings as part of the simulat
318318
- **Custom training description**
319319
- **Custom training duration (in minutes)**: The default value is 0, which means there's no specified duration for the training.
320320
- **Due date** section: In **Select a training due date**, choose one of the following values:
321-
- **30 days after simulation ends** (this is the default value)
321+
- **30 days after simulation ends** (this value is the default)
322322
- **15 days after simulation ends**
323323
- **7 days after simulation ends**
324324

@@ -427,7 +427,7 @@ On the **Select end user notification** page, select from the following notifica
427427
- **Do not deliver notifications**: No other configuration options are available on the page. Users don't receive **Training assignment notifications**, **Training reminder notifications** or **Positive reinforcement notifications** from the simulation. Select **Proceed** in the warning dialog.
428428

429429
- **Microsoft default notification (recommended)**: The notifications that users receive are shown on the page:
430-
- **Microsoft default positive reinforcement notification** (for the **How-to Guide** [social engineering technique](#select-a-social-engineering-technique), this is the only available notification)
430+
- **Microsoft default positive reinforcement notification** (for the **How-to Guide** [social engineering technique](#select-a-social-engineering-technique), this notification is the only available notification)
431431
- **Microsoft default training assignment notification**
432432
- **Microsoft default training reminder notification**
433433

defender-office-365/campaigns.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -329,7 +329,7 @@ The tabs in the campaign details flyout allow you to further investigate the cam
329329
- **SPF passed**: The sender was authenticated by the [Sender Policy Framework (SPF)](email-authentication-spf-configure.md). A sender that doesn't pass SPF validation indicates an unauthenticated sender, or the message is spoofing a legitimate sender.
330330

331331
- **Senders**
332-
- **Sender**: This is the actual sender address in the SMTP **MAIL FROM** command, which isn't necessarily the **From:** email address that users see in their email clients.
332+
- **Sender**: This address is the actual sender address in the SMTP **MAIL FROM** command, which isn't necessarily the **From:** email address that users see in their email clients.
333333
- **Total count**
334334
- **Inboxed**
335335
- **Not Inboxed**

0 commit comments

Comments
 (0)