August 20, 2026 SaaS Alerts release notes

Fortify Action Processor 3.46.0

New remediations

Ensure Office 365 management activity API is enabled for some workloads

Fortify now includes a remediation for this Microsoft Secure Score control. Applying the remediation starts Office 365 Management Activity API audit-feed subscriptions for Microsoft Entra ID, Exchange Online, SharePoint, OneDrive, and other supported workloads, making audit activity available to connected security-monitoring tools. Undo removes those subscriptions.

This remediation requires Microsoft 365 audit log search to already be enabled.

A new permission, ActivityFeed.Read (Office 365 Management APIs), is required for this action. Organizations with auto-upgrade enabled receive the permission automatically during their next connection refresh. Organizations with auto-upgrade disabled, or those with a broken connection, must reconnect before this action becomes available.

Disable Exchange Web Services (EWS)

Fortify now includes a remediation that disables Exchange Web Services (EWS) across the tenant. Undo restores the tenant's actual previous EWS configuration instead of always re-enabling the service.

Enhancements

Improved action descriptions throughout the portal

Descriptions, "what changes," and "what to expect" content have been rewritten across nearly all actions to provide clearer explanations of what each remediation changes, what it intentionally leaves unchanged, and what administrators can expect after it is applied.

Improved benchmark score accuracy

Partner-template and snapshot benchmark scores now reflect an organization's actual, currently maintained action record. This resolves an issue where a data inconsistency could cause benchmark scores to be calculated incorrectly.

Fixes

SMTP AUTH compliance evaluation

The Disable SMTP AUTH Basic Authentication - Company Wide and Per User remediation now correctly evaluates SMTP AUTH usage on shared mailboxes. This resolves a gap that could incorrectly identify a mailbox as safe to lock down while it was still actively using SMTP AUTH.

Microsoft Secure Score regression handling

Microsoft-scored actions no longer repeatedly enter a regressed state during nightly synchronization. Regressions now trigger only once when a change is detected.

Intune ADMX device-configuration deployment

Snapshots and templates that deploy Intune group-policy (ADMX) device configurations now deploy all configured values correctly. Previously, settings requiring associated values could be silently rejected during deployment or deployed with blank values while still reporting success. Existing snapshots receive this improvement automatically after their next refresh.

Undo and validation improvements

Several actions have been updated to restore existing tenant configurations more accurately during undo operations.

  • The Global Administrator role-grant action now removes only the role assignments created by Fortify and no longer revokes the role from administrators who already held it before Fortify applied the action.

  • Undo for the Authenticator anti-fatigue action no longer disables features such as number matching, biometrics, or additional context if those features were already enabled before the remediation was applied.

  • The User Consent (Integrated Apps) action now restores the tenant's previous consent policy instead of resetting it to Microsoft's most permissive configuration.

  • The Intune Device Cleanup Rule action now correctly removes the resources it creates and restores the tenant's previous threshold value.

  • A condition that could cause a valid Idle Session Timeout configuration to be reported as permanently non-compliant has been resolved.

  • The External Recipient Attachment Blocking actions now allow configured exclusions to be removed correctly. Compliance checks also no longer report manually disabled rules as compliant.

Cloud Apps improvements

Cloud Apps connection compliance now validates the current token status instead of relying on a one-time connection flag. Revoking access through Microsoft Defender is now reflected correctly, and three dependent actions no longer fail without explanation.

The Cloud Apps Discovery Policy action can now send alert notifications to a specified email address instead of only generating alerts within the Fortify console.

Multifactor authentication and Security Defaults

Undo behavior has been improved for the following remediations:

  • Ensure multifactor authentication is enabled for all users in administrative roles

  • Ensure multifactor authentication is enabled for all users

  • Enable Conditional Access policies to block legacy authentication

  • Phishing-resistant MFA

Undo operations now correctly reverse Security Defaults and related policies in licensing scenarios that previously prevented complete rollback. This resolves scenarios where Security Defaults could remain enabled after undo or be disabled when they had already been enabled before Fortify was applied.

The legacy-authentication remediation also no longer risks deleting a customer-created Conditional Access policy that shares the same display name.

Additional Microsoft Entra and Conditional Access fixes

  • The Ensure "Microsoft Azure Management" is limited to administrative roles action no longer fails during apply, undo, or validation because of an internal error.

  • The Block downloads on unmanaged devices action has been corrected. Previously, its stored policy rule could block downloads on managed devices instead of unmanaged devices.

  • The SASE Cloud Gateway action now reports a clear failure when a subscriber email address cannot be resolved and no longer remains incorrectly marked as applied after a failed run.

  • The Dynamic Bad IP Conditional Access action now evaluates the policy actively enforcing the block rather than a disabled duplicate policy.

  • An unused portal control was removed from the passkey-enablement action.

  • The Intune Enrollment Access Grant action no longer includes a device-compliance requirement, in accordance with Microsoft's guidance.

  • Conditional Access actions that target specific groups or roles now correctly honor the selected scope instead of silently remaining scoped to All Users.

  • Approximately 30 Conditional Access actions, including MFA, sign-in risk, user risk, session, device, and GenAI-related controls, now consistently manage the exact policies created or disabled by Fortify, even when customer-created policies use the same display name.

Exchange Online and Defender mail-flow improvements

  • The Mailbox Audit and Mail Tips actions now correctly apply configured values. Previously, Microsoft's default values could be applied while the requested values were still shown in history.

  • The Connection Filter (IP Allow List) action now restores allow lists exactly as they existed before undo, including IPv6 addresses and CIDR ranges.

  • The Safe Attachments action and the Safe Links email and Office Apps actions now prevent conflicting undo operations when they share the same underlying Exchange policy.

  • The Mail Forwarding Block action no longer modifies settings associated with other actions.

  • The Safe Documents and ATP Protection actions no longer interfere with their shared SharePoint, OneDrive, and Teams file-scanning setting. Undoing one action can no longer disable protection still managed by the other.

  • The Outlook Add-ins action now restores only the permissions it removed instead of regranting all permissions.

  • A Safe Attachments parameter for administrator notifications to external senders has been removed because Microsoft does not provide a way to apply that setting.

Data Loss Prevention improvements

All 29 Fortify DLP actions, including financial data, PII, HIPAA, GDPR, PCI-DSS, and regional breach-notification policies for Australia, Canada, the United Kingdom, and the United States, have been updated to better protect existing customer policies. Failed rule creation now rolls back only objects created by Fortify and no longer removes existing compliance policies owned by the customer.

Mailbox protocol and Defender block-list improvements

The mailbox protocol actions, including IMAP, POP3, MAPI, both SMTP AUTH variants, shared-mailbox sign-in, and mailbox audit bypass, now restore only the mailboxes modified by Fortify during undo operations. Previously, undo could re-enable protocols or sign-in settings on mailboxes that had been intentionally disabled before Fortify was connected.

Undoing either SMTP AUTH remediation independently no longer loosens the shared tenant-wide SMTP AUTH setting while the companion action remains applied.

The Defender block-list actions for domains and addresses, IPs, and URLs now validate the actual configured block list rather than simply checking whether any blocking exists.

SharePoint and OneDrive sharing improvements

The SharePoint and OneDrive sharing actions, including guest-user sharing, idle-session timeout, legacy authentication, organization-only sharing, managed external sharing, infected-file download blocking, and related OneDrive sharing controls, now restore the tenant's actual previous configuration during undo operations instead of applying fixed replacement values.

Purview audit-log search

The Purview Audit Log Search action now restores the tenant's previous setting during undo. Previously, there was no working undo path.

Additional reliability fixes

  • The External Recipient Attachment Blocking action no longer fails to apply in a new deployment where no exclusions have been configured.

  • The Intune Device Cleanup Rule action no longer reports a false regressed or non-compliant state for organizations that are not licensed for Intune.

  • Intune device-configuration snapshot deployment no longer leaves an empty orphaned policy behind when a deployment partially fails.

Teams meeting-policy improvements

  • The Bypass Lobby for PSTN Callers action no longer changes settings managed by the Auto Admit action, and vice versa during undo.

  • The Auto Admit action now restores custom meeting policies as well as Microsoft's built-in meeting policies.

  • The Teams Security End-User Reporting action now restores the related Defender-wide reporting configuration during undo.

  • The Approved Storage Services action no longer reports as permanently non-compliant after a successful apply and now restores the tenant's previous storage-provider selection during undo.

  • The External Access Restriction action now evaluates supported configurations correctly during compliance checks.

Entra directory and authorization improvements

  • The Custom Banned Passwords List action now merges Fortify's password list with existing tenant entries instead of replacing them. Undo restores the original customer-defined list.

  • The Password Protection action now restores the tenant's previous enforcement mode, Audit or Enforce, during undo.

  • The Guest Invite Restrictions action now restores the tenant's previous configuration instead of resetting it to Microsoft's most permissive setting.

Additional Intune and policy-management improvements

  • Twelve Intune device-configuration actions, including antivirus and firewall controls, jailbreak and root detection, password complexity, password length, password reuse, password expiration, device encryption, inactivity lock, email profiles, and remote wipe after failed sign-ins, now reapply their configured settings correctly when drift is detected. Undo operations restore the original configuration of affected objects instead of deleting or clearing policy objects.

  • Auto-remediated mailbox actions, including MAPI, mailbox audit bypass, and shared-mailbox sign-in, now restore the mailbox's previous state correctly during undo.

  • Intune Apple VPN configuration backups and snapshots now include network inclusion and network exclusion settings that were previously omitted.

  • Conditional Access policy snapshots whose source policies have been renamed no longer permanently fail deployment or drift comparison.

  • The SaaS Alerts Fortify Anti-Spam Global Outbound Policy Collection no longer includes the unsupported configuration options Send a BCC Copy of Outbound Spam and Notify Recipients on Outbound Spam, which Microsoft does not apply to custom outbound policies. The action that manages the default outbound policy is unchanged and continues to support both options.

  • The SaaS Alerts Fortify Anti-Phishing Policy Collection now includes a Targeted User Quarantine Policy parameter. This allows administrators to select the quarantine policy used when a protected user's identity is impersonated, consistent with existing controls for domain impersonation and mailbox intelligence. If left unconfigured, the action uses the same notify-and-self-release policy as the related settings.