July 30, 2026 SaaS Alerts release notes

Fortify Action Processor 3.30.2

Enhancements

  • Entra ID App Secret/Certificate Expiration

    Parameters have been added to support configurable alerting, including daily reminders and the ability to stop generating alerts after a configurable number of days following expiration.

  • New remediation: spo_block_onedrive_sync_unmanaged_devices

    A new remediation, spo_block_onedrive_sync_unmanaged_devices, has been added to block OneDrive for Business synchronization from unmanaged devices. Optional per-domain GUID enforcement is supported while preserving existing domain GUID configurations.

  • Update: fortify_M365GroupCreationDisabled false "regressed" events

    An issue causing false fortify_M365GroupCreationDisabled "regressed" events has been resolved. A case-sensitive comparison of directory-setting boolean values could result in false non-compliance findings, and regression deduplication state could be reset during synchronization, causing fortify.action.regressed alerts to be generated repeatedly. Compliance evaluation and regression tracking have been updated to prevent these issues. Affected organizations will automatically self-heal during the next synchronization cycle.

  • Core Security Baseline template customization

    An issue affecting mailbox exclusion lookups has been resolved. Under certain conditions, invalid mailbox filter processing could prevent mailbox exclusions from loading, causing "No Exclude mailbox(es) found" to appear and blocking template customization. Mailbox filtering now processes requests correctly and template customization functions as expected.

  • Anti-phish and anti-spam policy re-application

    An issue affecting anti-phish, anti-spam, outbound anti-spam, and anti-malware policy re-application has been resolved. Under certain conditions, policy re-apply operations could report success without correctly restoring policy priority, scope, and state. Re-apply operations now correctly enforce these settings across all supported policy types. Additionally, Microsoft Defender for Office 365 implementation status reporting now evaluates all configured policies rather than a single policy.

  • New remediation: fortify_blockInfectedFileDownload

    A new remediation, fortify_blockInfectedFileDownload, has been added to block downloads of SharePoint Online and OneDrive files that have been identified as infected by antivirus scanning. By default, SharePoint Online permits these downloads after displaying a warning. This remediation blocks the download instead. This is the first remediation to use the new SharePoint Online CSOM transport.

  • On-demand template benchmark processing

    An issue affecting on-demand template benchmark processing has been resolved. Large benchmark payloads could exceed Service Bus size limits, preventing benchmark jobs from being queued successfully while still returning a successful response. Synchronization history is now excluded from the benchmark payload, eliminating this limitation and reducing document size.

Ask AI - MSFT Agent

Fixes

Resolved an issue where concurrent requests could be lost

The assistant now correctly preserves multiple requests submitted in the same conversation at the same time. Previously, one request could occasionally overwrite another, causing part of the conversation history to disappear and preventing pending changes from being approved. All requests are now retained and processed independently.

Improved reliability when reconnecting during responses

The assistant now preserves conversation history and pending approvals if a browser tab is closed or a connection is interrupted while a response is being delivered. Previously, a disconnection during the final stage of a response could cause the entire exchange, including any pending approval actions, to be lost.