September 11, 2026 SaaS Alerts release notes
Fortify Action Processor 3.63.0
Enhancements
-
Teams External Access Settings snapshots: Teams External Access Settings are now supported as a snapshot type. You can capture, deploy, benchmark, and monitor external access configurations across managed organizations, including federation settings, allowed and blocked domains, and communication permissions for unmanaged Teams users and anonymous participants.
-
New "Exclude Global Administrators" option for the Block Device Code Authentication Flow action: Administrators can now configure whether Global Administrators are excluded from the Conditional Access policy created by this action. The setting is enabled by default to preserve existing behavior. Disabling the setting applies the policy to all users, including administrators. Before doing so, ensure you have an alternate administrative access path to the tenant.
-
More accurate snapshot benchmark results: Benchmark evaluations now use improved object matching and scoring logic, resulting in more accurate comparisons. Improvements include better handling of security group matching and missing configuration objects.
Fixes
-
Conditional Access benchmarks for certain cross-region public snapshots: Affected benchmark runs could incorrectly report failed results for snapshots cloned across regions. Newly cloned snapshots are unaffected. Existing cross-region clones should be re-cloned to resolve the issue.
-
Purview Data Loss Prevention snapshot processing for certain policy configurations: Capture and benchmark operations could fail for organizations using specific Data Loss Prevention rule configurations. Snapshot processing has been improved, and unsupported deployment scenarios now provide clear guidance. In some cases, policy conditions may need to be adjusted before recapturing a snapshot.
-
Purview snapshots in tenants using custom directory attributes: Snapshot creation and refresh operations for select Purview snapshot types could fail in tenants that use custom Entra ID extension attributes. Snapshot processing now correctly handles these attributes.
-
Teams Meeting Settings snapshot capture with cross-tenant access partners: An issue that prevented successful capture of Teams Meeting Settings snapshots in organizations with configured cross-tenant access partners has been resolved.
-
Snapshot deployment and deletion tracking: Deployment records and deletion results could be reported inaccurately in certain scenarios, including cases where failed deletions were reported as successful. Tracking accuracy has been improved across all snapshot types, helping ensure more reliable benchmark, drift monitoring, and removal operations.
-
Idle session timeout actions in certain organizations: Two idle session timeout actions could not be applied in some environments. These actions now correctly identify and update the organization's default timeout policy and preserve existing administrator-defined settings during undo operations.
-
Improved guidance for lobby restriction enforcement: The "Restrict dial-in users from bypassing a meeting lobby" action now provides clear guidance when prerequisite Teams meeting policy settings must be configured before the action can be successfully applied.
-
Concurrent Defender action application: Applying certain Defender-related actions at the same time could cause one action to fail. Processing has been updated to ensure both actions complete successfully when applied together.
-
Conditional Access undo operations involving trusted named locations: Undo operations no longer report errors when trusted named locations cannot be removed. The undo process now completes successfully while preserving supported Microsoft configuration requirements.
Ask AI - Microsoft Teams Agent
Enhancements
-
Fortify AI assistant in Microsoft Teams. The Fortify AI assistant is now available directly in Microsoft Teams. You can ask questions, approve changes, and collect exports without leaving Teams. The Teams experience uses the same organizations, permissions, and approval workflow as the Fortify web portal.
-
Ask AI questions directly from Teams. You can ask anything available in the Fortify web chat, including identity and access, email and collaboration, threat protection, compliance, cloud app security, and Fortify posture questions across the Microsoft 365 organizations connected to your Fortify account.
-
Approve changes from Teams. Changes proposed by the assistant can be approved or declined directly from the action card it sends. Approval must be completed using the card controls; typing a response such as "yes" does not authorize a change.
-
Export delivery through OneDrive. Exports can now be delivered as files saved to your personal OneDrive, with links provided to open or download them. If an export is declined, no file is saved, although the information remains available in the conversation.
-
Built-in Teams guidance. Use the /help command at any time to receive an overview of the assistant's capabilities and available tasks.
-
Microsoft Teams deployment and troubleshooting. Organizations can connect their Microsoft 365 tenant to Microsoft Teams, make the Fortify Agent application available through Microsoft Teams administration settings, and grant access to specific users or groups from the Fortify web portal. The Teams app is automatically installed for authorized users. If the application is not available, the assistant can help identify Teams configuration settings that may be preventing deployment. Deployment requirements and troubleshooting guidance, including administrator consent, Teams app availability settings, access management, expected propagation delays, and troubleshooting procedures, are documented in Ask AI (MSFT Agent).
-
Extended audit and activity investigations. Audit and activity questions now support significantly longer historical lookback periods. Large date ranges are automatically divided into consecutive searches and combined into a single result, allowing investigations that span multiple years.
-
Expanded SharePoint access visibility. You can now ask who has access to a SharePoint site and receive expanded results that include SharePoint groups and their individual members.
-
Enhanced mailbox investigations. Mailbox access investigations now identify whether access originated from the mailbox owner, a user with delegated permissions, or an application with ongoing permissions.
-
Faster and more precise posture reporting. Posture questions now return specific numerical results rather than estimated responses and provide significantly improved performance when evaluating multiple organizations.
-
Large export handling. Exports that exceed single-file limits are now automatically split into multiple files, with one file generated per organization instead of rejecting the export request.
-
Sign-in activity searches. Requests for recent sign-in activity automatically expand the search window to the previous seven days before reporting no results.
