October 1, 2026 SaaS Alerts release notes
Ask AI - MSFT Agent
Enhancements
Manage Microsoft Defender for Endpoint indicators through the assistant
You can now ask the assistant to list, add, modify, or remove Microsoft Defender for Endpoint indicators. These include allow, audit, warn, and block entries for file hashes, certificates, IP addresses, URLs, and domains. Before any change is made, the assistant provides a preview for approval that shows what will happen to any indicators already configured for that value. The preview also warns when a new indicator would have no effect, such as an allow entry alongside a block entry for the same file or certificate, or a block entry alongside an allow entry for the same website or IP address. If an organization does not have Microsoft Defender for Endpoint, the assistant indicates this instead of attempting the action.
Copy Intune scripts between organizations.
You can now ask the assistant to copy a PowerShell script, remediation script, or macOS shell script from one organization to another. Scripts are copied exactly as they are and their contents are not shown in the chat. Before the copy is completed, the approval prompt shows the source organization, destination organization, script size, and a fingerprint of the script content. If the source script changes before approval, the assistant asks you to review the copy again before proceeding. Script assignments are not copied, allowing you to choose assignments separately in the destination organization.
Fixes
Improved accuracy when checking Defender for Endpoint indicators.
The assistant now checks the Microsoft Defender for Endpoint indicator list directly when validating certificate and file indicators. This resolves an issue where existing indicators could be reported as missing even though they were present in the Defender portal.
