Skip to content

Commit dc0baad

Browse files
authored
Merge branch 'public' into patch-1
2 parents 73f11db + 53bfe1a commit dc0baad

File tree

9 files changed

+80
-9
lines changed

9 files changed

+80
-9
lines changed

CloudAppSecurityDocs/governance-actions.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -83,6 +83,13 @@ The following governance actions can be taken for connected apps either on a spe
8383

8484
- **Trash** – Move the file to the trash folder. (Box, Dropbox, Google Drive, OneDrive, SharePoint)
8585

86+
> [!NOTE]
87+
> These actions are restricted to users with specific administrative roles. If the options described are not visible or accessible, please confirm with your system administrator that your account has one of the following roles assigned:
88+
- Security Operator
89+
- Security administrator
90+
- Global administrator
91+
- Cloud app security administrator
92+
8693
:::image type="content" source="media/governance-actions/governance-actions-dropbox-google-workspace.png" alt-text="Screenshot that shows malware governance actions." lightbox="media/governance-actions/governance-actions-dropbox-google-workspace.png":::
8794

8895
> [!NOTE]

CloudAppSecurityDocs/release-notes.md

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,9 +29,18 @@ For news about earlier releases, see [Archive of past updates for Microsoft Defe
2929

3030
## June 2025
3131

32+
### “Behaviors” data type in Microsoft Defender for Cloud Apps - General Availability
33+
34+
The **Behaviors** data type significantly enhances overall threat detection accuracy by reducing alerts on generic anomalies and surfacing alerts only when observed patterns align with real security scenarios. You can now use **Behaviors** to conduct investigations in [Advanced Hunting](https://learn.microsoft.com/defender-xdr/advanced-hunting-overview), build better [custom detections](https://learn.microsoft.com/defender-xdr/custom-detection-rules) based on behavioral signals, and benefit from automatic inclusion of context-related behaviors into [incidents](https://learn.microsoft.com/defender-xdr/incidents-overview). This provides clearer context and helps security operations teams to reduce alert fatigue, prioritize, and respond more efficiently.
35+
36+
For more information, see:
37+
- [Investigate behaviors with advanced hunting](/defender-cloud-apps/behaviors).
38+
- [TechCommunity Blog](https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/transform-the-way-you-investigate-by-using-behaviors--new-detections-in-xdr-star/3825154).
39+
3240
### New Dynamic Threat Detection model
3341

3442
Microsoft Defender for Cloud Apps new dynamic threat detection model continuously adapts to the ever-changing SaaS apps threat landscape. This approach ensures your organization remains protected with up-to-date detection logic without the need for manual policy updates or reconfiguration. Several legacy anomaly detection policies have already been seamlessly transitioned to this adaptive model, delivering smarter and more responsive security coverage.
43+
3544
For more information, see [Create Defender for Cloud Apps anomaly detection policies](anomaly-detection-policy.md).
3645

3746

@@ -111,7 +120,7 @@ Defender for Cloud Apps customers can now configure Role-Based Access Control (R
111120
For more information, see:
112121

113122
- [Configure admin access](/defender-cloud-apps/manage-admins)
114-
- [Investigate behaviors with advanced hunting (Preview)](/defender-cloud-apps/behaviors)
123+
- [Investigate behaviors with advanced hunting](/defender-cloud-apps/behaviors)
115124

116125
## February 2025
117126

defender-endpoint/ios-new-ux.md

Lines changed: 61 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -20,22 +20,19 @@ search.appverid: met150
2020

2121
# User Experiences in Microsoft Defender for Endpoint on iOS
2222

23-
As part of our ongoing commitment to delivering an exceptional user experience, we're excited to announce a series of upcoming enhancements to the user interface and overall experience of our **Microsoft Defender for Endpoint** mobile app.
24-
25-
These updates are designed to improve usability, streamline navigation, and ensure that app meets the evolving needs of our users.
23+
As part of our ongoing commitment to delivering an exceptional user experience, we are excited to announce a series of upcoming changes to the user interface and overall experience of our MDE mobile app. These enhancements are designed to improve usability, streamline navigation, and ensure our app meets the evolving needs of our users. This document outlines the planned updates for MDE Mobile users.
2624

2725
## Key changes
2826

29-
We're pleased to introduce the Device Protection feature card for our enterprise users, which includes **Web Protection**, **Device Health**, and **Jail break** features that are designed to be more user-friendly and accessible.
30-
31-
The updated cards also include **recommendation cards**, which prominently display any active alerts, keeping you informed. Features are now displayed as tiles to improve user experience and navigation efficiency.
27+
We are pleased to introduce the **Device Protection** feature card for our enterprise users which includes Web Protection, Device Health and Jail break feature that has been designed to be more user-friendly and accessible. The updated feature cards now include recommendation cards. The first recommendation card will prominently display any active alerts, ensuring you stay informed. Additionally, a list of features will now be presented in the form of tiles as a part of L2 screens enhancing ease of use and navigation.
3228

3329
**The main changes involved are**:
3430

3531
- Main dashboard changes
3632
- List the features inside one feature card
3733
- Detailed features experience
3834
- Recommendation cards for alerts
35+
- Onboarding screens
3936

4037
### Main Dashboard changes
4138

@@ -72,3 +69,61 @@ The structure of the dashboard is updated to include a recommendation card that
7269
2. **Device Health (iOS Update)**
7370

7471
:::image type="content" source="media/mde-ios-device-health-rec-card.png" alt-text="Screenshot that shows the device health recommendation card feature on the MDE iOS app." lightbox="media/mde-ios-device-health-rec-card.png":::
72+
73+
### Onboarding Screens
74+
75+
This sections details these changes:
76+
77+
* VPN Permission flow while Onboarding
78+
79+
* VPN Permission flow after Onboarding
80+
81+
* TVM EUPI Screen
82+
83+
### VPN Permission flow while Onboarding
84+
85+
This is the main VPN Permission screen that will appear to the enterprise's users as per our latest rollout of enhancements in the application.
86+
87+
:::row:::
88+
:::column span="":::
89+
90+
#### Before
91+
92+
:::image type="content" source="media/ios-vpn-before.png" alt-text="Screenshot that shows the Microsoft Defender for Endpoint mobile iOS setup before the new update." lightbox="media/mde-ios-main-dash-new.png":::
93+
94+
:::column-end:::
95+
:::column span="":::
96+
97+
#### Now
98+
99+
:::image type="content" source="media/ios-vpn-after.png" alt-text="Screenshot that shows the Microsoft Defender for Endpoint mobile iOS setup after the new update." lightbox="media/mde-ios-main-dash-new.png":::
100+
101+
:::column-end:::
102+
:::row-end:::
103+
104+
### VPN Permission flow after Onboarding
105+
106+
This screen is seen when the VPN configuration is deleted from user's device, and the VPN needs to be re-enabled.
107+
108+
:::image type="content" source="media/ios-vpn-re-enable.png" alt-text="Screenshot that shows the Microsoft Defender for Endpoint mobile iOS re-enable screen." lightbox="media/mde-ios-list-new.png":::
109+
110+
### TVM EUPI Screen
111+
112+
We've enhanced the TVM EUPI screen as made it align with our current code flow.
113+
114+
:::row:::
115+
:::column span="":::
116+
117+
#### Before
118+
119+
:::image type="content" source="media/ios-tvm-before.png" alt-text="Screenshot that shows the Microsoft Defender for Endpoint mobile iOS TVM EUPI screen before the new update." lightbox="media/mde-ios-main-dash-new.png":::
120+
121+
:::column-end:::
122+
:::column span="":::
123+
124+
#### Now
125+
126+
:::image type="content" source="media/ios-tvm-after.png" alt-text="Screenshot that shows the Microsoft Defender for Endpoint mobile iOS TVM EUPI after the new update." lightbox="media/mde-ios-main-dash-new.png":::
127+
128+
:::column-end:::
129+
:::row-end:::
59.2 KB
Loading
28.1 KB
Loading
78 KB
Loading
50.2 KB
Loading
33.2 KB
Loading

defender-office-365/anti-malware-protection-about.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.collection:
1717
description: Admins can learn about anti-malware protection and anti-malware policies that protect against viruses, spyware, and ransomware in Exchange Online Protection (EOP).
1818
ms.custom: seo-marvel-apr2020
1919
ms.service: defender-office-365
20-
ms.date: 05/13/2025
20+
ms.date: 06/24/2025
2121
appliesto:
2222
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Exchange Online Protection</a>
2323
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -94,7 +94,7 @@ In the Microsoft Defender portal, you can select from a list of additional file
9494

9595
- **Default file types**: `ace, ani, apk, app, appx, arj, bat, cab, cmd, com, deb, dex, dll, docm, elf, exe, hta, img, iso, jar, jnlp, kext, lha, lib, library, lnk, lzh, macho, msc, msi, msix, msp, mst, pif, ppa, ppam, reg, rev, scf, scr, sct, sys, uif, vb, vbe, vbs, vxd, wsc, wsf, wsh, xll, xz, z`.
9696

97-
- **Additional file types to select in the Defender portal**: `7z, 7zip, a, accdb, accde, action, ade, adp, appxbundle, asf, asp, aspx, avi, bas, bin, bundle, bz, bz2, bzip2, caction, cer, chm, command, cpl, crt, csh, css, der, dgz, dmg, doc, docx, dos, dot, dotm, dtox [sic], dylib, font, fxp, gadget, gz, gzip, hlp, Hta, htm, html, imp, inf, ins, ipa, isp, its, js, jse, ksh, Lnk, lqy, mad, maf, mag, mam, maq, mar, mas, mat, mau, mav, maw, mda, mdb, mde, mdt, mdw, mdz, mht, mhtml, mscompress, msh, msh1, msh1xml, msh2, msh2xml, mshxml, msixbundle, o, obj, odp, ods, odt, one, onenote, ops, os2, package, pages, pbix, pcd, pdb, pdf, php, pkg, plg, plugin, pps, ppsm, ppsx, ppt, pptm, pptx, prf, prg, ps1, ps1xml, ps2, ps2xml, psc1, psc2, pst, pub, py, rar, rpm, rtf, scpt, service, sh, shb, shs, shtm, shx, so, tar, tarz, terminal, tgz, tmp, tool, url, vhd, vsd, vsdm, vsdx, vsmacros, vss, vssx, vst, vstm, vstx, vsw, w16, workflow, ws, xhtml, xla, xlam, xls, xlsb, xlsm, xlsx, xlt, xltm, xltx, xnk, zi, zip, zipx`.
97+
- **Additional file types to select in the Defender portal**: `7z, 7zip, accdb, accde, action, ade, adp, appxbundle, asf, asp, aspx, avi, bas, bin, bundle, bz, bz2, bzip2, caction, cer, chm, command, cpl, crt, csh, css, der, dgz, dmg, doc, docx, dos, dot, dotm, dtox [sic], dylib, font, fxp, gadget, gz, gzip, hlp, Hta, htm, html, imp, inf, ins, ipa, isp, its, js, jse, ksh, Lnk, lqy, mad, maf, mag, mam, maq, mar, mas, mat, mau, mav, maw, mda, mdb, mde, mdt, mdw, mdz, mht, mhtml, mscompress, msh, msh1, msh1xml, msh2, msh2xml, mshxml, msixbundle, o, obj, odp, ods, odt, one, onenote, ops, os2, package, pages, pbix, pcd, pdb, pdf, php, pkg, plg, plugin, pps, ppsm, ppsx, ppt, pptm, pptx, prf, prg, ps1, ps1xml, ps2, ps2xml, psc1, psc2, pst, pub, py, rar, rpm, rtf, scpt, service, sh, shb, shs, shtm, shx, so, tar, tarz, terminal, tgz, tmp, tool, url, vhd, vsd, vsdm, vsdx, vsmacros, vss, vssx, vst, vstm, vstx, vsw, w16, workflow, ws, xhtml, xla, xlam, xls, xlsb, xlsm, xlsx, xlt, xltm, xltx, xnk, zi, zip, zipx`.
9898

9999
When files are detected by the common attachments filter, you can choose to **Reject the message with a non-delivery report (NDR)** or **Quarantine the message**.
100100

0 commit comments

Comments
 (0)