Malware automated remediation in Defender for Storage
Malware automated remediation in Defender for Storage
March 31, 2026
Malware automated remediation in Defender for Storage malware scanning is now generally available.
Defender for Cloud now lets you configure automatic soft deletion of detected malicious blobs during on-upload or on-demand scanning. Auto-deletion keeps harmful content in quarantine and makes it recoverable for further investigation.
You can enable or disable automated malware remediation at the subscription level or the storage account level in Microsoft Defender for Cloud in the Azure portal or with an application programming interface (API).
Support for additional Azure regions for Defender for APIs and API security posture management with Defender CSPM
Microsoft Defender for APIs and API security posture management with Defender CSPM has expanded to provide its capabilities in the following Azure regions:
- Sweden Central
- Sweden South
- Germany West Central
- Germany North
- Italy North
- France Central
- France South
- Norway East
- Norway West
- Switzerland North
- Switzerland West
- Korea Central
- Korea South
- South Africa North
- South Africa West
Customers who have Azure API Management services in these regions can now use the capabilities offered by Microsoft Defender for APIs and API security posture management with Defender CSPM. API discovery and security posture capabilities in Defender CSPM for Azure Function Apps and Azure Logic Apps have also been expanded to these regions. This feature is still in Preview.
AI model security for Azure Machine Learning (Preview)
Microsoft Defender for Cloud now offers AI model security in preview for Azure Machine Learning registries and workspaces. AI model security helps security teams discover and scan custom AI models for risks before deployment, and review findings in Defender for Cloud.
By using AI model security, you can:
- Discover AI models in Azure Machine Learning registries and workspaces.
- Scan supported model artifacts for malware and unsafe operators.
- Review security findings and remediate surfaced issues in Defender for Cloud.
- Perform CLI-based scanning for CI/CD integrations.
Expanded multicloud coverage for AWS and GCP (Preview)
March 29, 2026
Microsoft Defender for Cloud expands multicloud posture management with broader native coverage for AWS and GCP. This update adds discovery and posture assessment for additional resource types across compute, databases, storage, analytics, networking, identity, secrets, DevOps, and AI/ML services.
Asset inventory: Newly supported AWS and GCP resources are now discovered and visible in the Asset inventory experience.
Security recommendations: Approximately 150 new recommendations help identify misconfigurations and posture gaps across the newly supported resources.
Regulatory compliance: Existing compliance frameworks now include the new recommendations, providing more complete compliance assessments across multicloud environments.

