Report an Incident Become a Partner Careers Contact
Book a Demo
Threat Research

Microsoft Digital Defense Report 2026: Reading It Against Your Own Detections

W Wizard Cyber 5 October 2026 7 min read
A grid of squares representing attack techniques, most filled solid red for techniques a detection would catch and six left hollow for techniques where nothing would fire, beside the question "Would your detections see it?"

Microsoft has published the Microsoft Digital Defense Report 2026, covering the year to 30 June 2026. Most of what gets written about it over the next month will be a summary of it. The report does not need another summary. It needs a reader willing to ask a harder question of their own estate.

That question is not "what are the threats this year". It is "would we have seen any of this".

Three findings that should change something

The report is long and most of it is context. Three findings carry a direct operational consequence.

The way in is still a valid login

Microsoft reports that user execution and valid accounts remain the most common techniques for initial access, and that 52.2% of valid account intrusions involved follow-on credential theft.

Read that twice. The intrusion that matters most often does not look like an intrusion. It looks like a login, from an account that is supposed to exist, doing things that account is allowed to do. There is no malware to catch and no exploit to patch. What there is, if you are looking for it, is a pattern: a sign-in that does not fit the account's history, followed by activity that does not fit the role.

If your detection strategy is weighted towards malicious files and known-bad infrastructure, this is the finding that should move budget.

There is a second consequence, and it is about investigation rather than detection. An alert on a valid account looks benign on first inspection, because on first inspection it genuinely is: a real user, a real device, a permitted action. That 52.2% is the half of the story that only appears when somebody keeps going after the obvious answer has already presented itself. A shallow investigation does not get the wrong answer here. It gets a plausible one, writes it down, and closes.

AI is now on both sides of the line

Microsoft notes that 88% of enterprises are already experimenting with AI agents, and sets out five risk classes for attacks against agentic systems, including prompt manipulation, data exposure, identity compromise and excessive agency.

The useful way to read that is not as a warning about AI in the abstract. It is this: an agent you deploy is an identity with permissions. It authenticates, it holds access, it acts on systems, and it can be manipulated into acting on behalf of someone who is not you. Every control you apply to a privileged human account is a control that now needs an answer for a non-human one. Most organisations experimenting with agents this year have not yet had that conversation with their security team.

Ransomware is the end of the chain, not the start

Microsoft reports a 15.8% year-on-year increase in ransom detonations, with critical manufacturing most heavily affected.

Detonation is the last step. By the time it happens the access was bought or phished weeks earlier, the reconnaissance is done and the data is already gone. Microsoft puts data theft in 63% of intrusions. The window where an intrusion is cheap to stop sits a long way before the ransom note, and it is a window measured in the quality of your detection and the speed of your investigation rather than in the quality of your backups.

The gap a threat report cannot close

Here is the problem with annual threat reports, and it is not the reports' fault.

A report tells you what happened to other organisations. It cannot tell you whether your estate would have noticed the same thing happening to you. Reading one produces a reliable feeling of being informed. It does not change a single analytic rule, and the feeling and the coverage are easy to confuse.

The work that closes the gap is unglamorous and specific: take each technique the report names, find the detection you already have for it, and be honest about the ones where you find nothing. That is a different exercise from reading, it takes real hours, and it is the reason most threat reports are read once and filed.

Reading it as a work list

If you do nothing else with the 2026 report, do this.

  1. Take the techniques, not the headlines. The statistics make the news. The technique names are the part you can act on.
  2. Map each one to a detection you actually have. Not a product that claims the category. A rule, with a name, that fires in your environment.
  3. For each one with no detection, make a decision and write it down. Build it, accept the risk, or cover it another way. All three are legitimate. Leaving it undecided is not.
  4. Date the exercise. Next year's report lands twelve months from now. The value of this year's is knowing what changed in between.

That list is not sophisticated. Almost nobody completes it, which is precisely why it is worth doing.

How we handle this

We have run Microsoft Sentinel since 2019 and we are a Microsoft Solutions Partner, so Microsoft's threat reporting is not external news to us. It arrives in the same place our own intelligence does.

There are two halves to what happens next, and they answer the two questions the report raises.

Coverage first. Within CYBERSHIELD AI, intelligence is ingested continuously from vendor feeds, research publications and Microsoft Defender Threat Intelligence, and the actors, techniques and indicators are extracted from it. Then the step most intelligence programmes skip: each reported technique is checked against whether the customer's own detections would actually see it, and where the answer is no, that gap is raised to detection engineering as work rather than noted as a risk. That is the whole difference between intelligence and a newsletter. A feed you have to triage yourself is work. Intelligence is the part where somebody has already worked out which of it applies to you.

Then depth. Our Investigation Agent works an alert through to a verdict. Where the evidence does not settle it, the same agent changes gear rather than handing on: it opens an Advanced Investigation, forms hypotheses about what actually happened, tests each against the estate, and resolves what the first pass could not. A standard investigation averages three minutes thirty. One that needs the deeper pass averages seven minutes fifty. The agent exhausts itself before it costs anybody else their time, and only then does it escalate to a human analyst, who still signs the verdict before it reaches you.

That second half matters most on exactly the finding this report leads with. An intrusion that looks like a login is the case a first pass closes, because the first pass finds a real user doing something they are allowed to do and that is a perfectly good answer. It is the second pass, the one that asks what else would be true if this account were not the person it claims to be, that finds the 52.2%.

The report's own conclusion

Microsoft's recommendations this year are phishing-resistant authentication, identity governance, correlating intelligence across systems, and a shift towards continuous threat exposure management rather than reactive response.

None of that is a product. All of it is a discipline, and the gap between organisations that have it and organisations that have bought tools adjacent to it is the gap the next twelve months of this report will describe.

The report is available from Microsoft. It is worth the time. What it is worth considerably more of is the afternoon afterwards, spent against your own detection coverage.

Microsoft Digital Defense ReportThreat IntelligenceMicrosoft SentinelDetection EngineeringIdentityAgentic AIRansomwareSecurity Operations

Ready to see the agents work?

Book a demo of CYBERSHIELD AI against a real scenario.