September 25, 2026 SaaS Alerts release notes
Ask AI - MSFT Agent
Enhancements
Investigations provide more context for SaaS Alerts detections
When investigating a SaaS Alerts alert, the assistant now starts with the alert and reviews related sign-in activity, inbox rules, forwarding activity, and file activity. It also recognizes when an account was disabled by SaaS Alerts Respond as an automated response action rather than the cause of the alert.
User queries return more specific results
Queries about users now return the users who match the requested criteria. When some organizations return incomplete data, complete results are shown where available and incomplete organizations are identified, with an option to export the results.
User and organization matching is more accurate
Short account names can now be matched as sign-in names. Questions about inactive users are now supported in tenants without Entra ID P1. Organization matching also recognizes website addresses and onmicrosoft.com domains more effectively.
Microsoft 365 connection and policy coverage is more comprehensive
Connection checks now validate Entra ID, Exchange Online, Purview, and SharePoint separately. Coverage for Safe Links and anti-phishing policies now includes Standard and Strict preset policies.
Settings reviews and investigation summaries are more efficient
Reviews of settings such as MFA registration now retrieve configuration data directly instead of starting a full investigation. Requests to summarize or translate an investigation now use the existing investigation results. Investigation summaries also retain information about checks that could not be completed.
Guidance for unsupported changes is clearer
When a requested change must be performed outside the assistant, such as SaaS Alerts suppression settings, Power Filters, or third-party products, the assistant now explains where those settings are managed and what Microsoft 365 actions are available.
Large compliance policy sets are handled more effectively
When the number of DLP or compliance policies exceeds the amount that can be processed at one time, the assistant identifies that the results are incomplete and allows policies to be reviewed individually.
Teams setup and access information is more detailed
Teams setup guidance now identifies the specific Teams admin center location where the app is made available. The assistant also provides more information when installation does not reach all users and explains why organization management must be performed in the web portal.
Fixes
Investigation results include additional sign-in and mailbox activity
Investigations now review silent application sign-ins, inbox rules created in Outlook desktop, and mailbox activity recorded under additional audit categories before reporting that no activity was found. Results also indicate when activity is outside available audit log time ranges.
Inbox rule analysis provides more complete results
Investigations now recover additional information about deleted inbox rules and provide more complete visibility into inbox rule activity, with forwarding and deletion rules prioritized in results.
Recipient lookups return the requested result
Recipient searches now return the specific person, group, or address that was requested.
Approved changes and rollout plans execute correctly
Approved multi-step changes and rollout plans now run as expected. Organization matching issues that could prevent approved plans from running have also been corrected.
Secure Score recommendation status is reported accurately
Recommendations addressed through accepted risk, alternative mitigations, or third-party solutions are now reported as dismissed with the corresponding reason and configuration details.
Reporting metrics and license counts are more accurate
Rankings, totals, progress indicators, and related calculations now align with the underlying data. Free sign-up licenses are no longer counted as unassigned licenses.
Device registration changes require only one approval
Changes to Entra device registration settings now require a single approval.
DLP recommendations better match regional data
Suggested sensitive information types now align more closely with the country and language of the data being evaluated.
Organization names containing commas are handled correctly
Organizations with commas in their names are now processed correctly in templates and related workflows.
