SOC Weekly Brief The week in the Microsoft security stack, distilled

Latest issue · Week 30 · 4 min read

July 20 – July 27, 2026

Act by

  • 26 Oct 2026 — Microsoft Entra ID is retiring custom CSS positioning properties in company-branded sign-in pages. As of 21 July 2026, tenants not already using these properties can no longer configure them, and on 26 October 2026 the positioning properties are retired globally — logos, images, and text stay visible but revert to their default placement, with no migration path, so any tenant still relying on them must remove them before the cutover. Microsoft frames this as an anti-phishing measure: removing arbitrary layout control shrinks the room to build convincing look-alike sign-in pages. Inventory your branded sign-in configurations now, confirm whether any use positioning CSS, and plan the visual change ahead of enforcement rather than discovering it when the page shifts. (Microsoft Entra Blog)

What changed

Microsoft Entra extended phish-resistant, passwordless authentication to Linux desktops, bringing Linux to parity with Windows and macOS with support for Ubuntu 24.04 and 26.04 and RHEL 8, 9, and 10. The same July roundup raised the passkey (FIDO2) policy to a dedicated 20 KB allocation and increased the maximum number of passkey profiles per tenant from three to ten, giving larger organizations room to register more device-bound and platform authenticators under policy. For a SOC steering users off telephony MFA ahead of the passkey-default and SMS/voice retirement dates, this closes a gap for Linux-based admins and engineers who previously had no first-party phishing-resistant option. (Microsoft Entra Blog)

Microsoft Defender for Cloud took database-level recommendations for SQL Vulnerability Assessment to general availability on 26 July. Instead of one grouped finding per server or instance, each SQL VA rule now surfaces as its own recommendation reported directly on the affected database, so a single misconfigured database no longer hides behind a green server-level rollup. The GA recommendations feed the risk-based Cloud Score rather than the classic Secure Score, and each finding can be fixed, approved as a per-rule-and-resource baseline, or exempted at the subscription or management-group level. This is the GA of the per-database experience that entered preview back in February, and it lands automatically wherever SQL VA is already scanning. (Microsoft Defender for Cloud release notes)

Azure DDoS Protection added custom policy in public preview, letting teams fine-tune mitigation behavior and set protocol-specific detection thresholds for supported protected resources. Until now the mitigation thresholds were adaptive and largely opaque; custom policy lets you align protection with a workload's known traffic profile upfront and tune thresholds for high-risk services to cut false positives and improve resiliency. For teams that run internet-facing services behind Azure DDoS Protection, it is a chance to test tighter, workload-specific policies before an attack rather than tuning under fire. (Microsoft Azure Networking Blog)

Microsoft Defender for Identity moved migration of sensors from v2.x to v3.x to general availability, now including domain controllers running Windows Server 2025, and the Sensors page adds tooltips explaining why a server is marked not ready. The v3.x sensor line is the one that carries the newer detection and identity-posture coverage — including AD FS, AD CS, and Entra Connect role support — so getting the fleet migrated is what actually turns on the latest identity detections. Alongside GA, Defender for Identity now enables RPC auditing on domain controllers automatically when you upgrade to sensor 3.0.8 or later, removing the manual tag step that some advanced detections depended on, and it added SaaS-app password risk from Defender for Cloud Apps connectors to the Password protection page in preview. Prioritize the sensor migration where identity detection coverage matters most. (Microsoft Defender for Identity what's new)

Worth knowing

Microsoft's Q2 2026 email threat landscape report is worth a read for anyone tuning mail and collaboration detections. Microsoft flagged roughly 7.6 billion email-based phishing threats across the quarter, with monthly volume easing from 2.7 billion in April to 2.4 billion in June as the March disruption of the Tycoon2FA phishing-as-a-service platform kept biting — phishing tied to the platform fell about 92% from its pre-takedown baseline, and QR-code and CAPTCHA-gated phishing collapsed alongside it. Credential phishing still dominated at 94–96% of payload-based attacks, and two trends stand out for a SOC: Teams-based abuse kept climbing, with weekly malicious call attempts up roughly 80% since early 2026 and vishing running near ten times its mid-2025 baseline (peaking 14:00–20:00 UTC on weekdays), and ICS calendar-file lures quadrupled in June. One scripted BEC campaign reached more than 67,000 users across 42,000 organizations in under three hours using Python mail libraries and Amazon SES. Watch Teams vishing and calendar-invite delivery, not just inbound mail. (Microsoft Security Blog)

Microsoft also detailed a tie-up that brings Microsoft Incident Response to AXA XL cyber-insurance policyholders, coordinating the technical, business, and insurance sides of a live incident under one response. It is a partnership announcement rather than a product change, but it is a useful signal for teams whose incident runbooks intersect with a cyber policy: knowing in advance how an insurer-aligned IR engagement is triggered and coordinated shortens the scramble when an incident is declared. (Microsoft Security Blog)