What’s New in the Hybrid Data Center & Microsoft | May 2026

Hybrid Data Center Team

eGroup

Organizations are facing accelerated platform modernization decisions across hybrid infrastructure and Microsoft cloud services. This month’s updates focus heavily on AI governance, platform lifecycle changes, ransomware resilience, and operational modernization spanning VMware, Nutanix, Azure, Copilot, Teams, and Purview. Security hardening, compliance readiness, and AI operational controls continue to converge as enterprises balance modernization with risk reduction.


What’s the Buzz at eGroup?

Only 5 Days Until Our Spring Microsoft Virtual Roadshow!

Haven’t you saved your seat for our biggest virtual event of the year? 😲 

Don’t miss the chance to get a front‑row seat to what’s next across Data and AI, Azure, Microsoft 365, and Security. We’ll walk through how teams are working more efficiently with Microsoft tools, tightening security across their environments, and using AI to automate workflows and improve decision‑making. Leave with actionable ideas to simplify operations, support collaboration, and move your business forward. Register today!

Tuesday, May 19th | 1PM-5PM EST | Day One: Azure + Security

Explore Azure trends, cloud migration strategies, application modernization with GitHub Copilot, how to secure workspaces using Intune, Azure Virtual Desktop, and Nerdio, and how to protect hybrid and multi-cloud environments with Defender for Cloud.

Wednesday, May 20th | 1PM-5PM EST | Day Two: Microsoft 365 + Security

Dive into modern threats, E7 licensing, endpoint mgmt with Intune and Autopilot, identity transformation with a cloud-only strategy, and AI-readiness with Copilot governance, Purview, and Agent 365.

Thursday, May 21st | 1PM-5PM EST | Day Three: Data & AI

See what’s new with M365 Copilot Wave 3, Work IQ, and Agent 365, then explore Power Platform vibe coding, data governance with Purview, and frameworks for scaling an AI program.


What’s New in the Hybrid Data Center?

Cisco

Hybrid Operations and Zero Trust Expansion
Cisco continues expanding its hybrid infrastructure management and security portfolio with investments in automation, visibility, and AI security. The company is also emphasizing lifecycle risk reduction and Zero Trust enforcement across modern enterprise infrastructure.

View full Cisco update
  • Cisco Nexus Dashboard Simplifies Hybrid Fabric Operations
    Cisco Nexus Dashboard enables centralized lifecycle management, automation, analytics, and visualization for ACI, VXLAN EVPN, SAN, and traditional data center fabrics through a single management plane. This helps infrastructure teams reduce operational complexity, improve segmentation visibility, and standardize management across hybrid environments.
  • Cisco Announces Intent to Acquire Astrix Security
    Cisco announced plans to acquire Astrix Security to strengthen AI security and Zero Trust capabilities focused on the emerging “agentic workforce.” The acquisition expands Cisco’s visibility, governance, and automated threat detection capabilities for AI agents and third-party SaaS integrations, helping organizations improve identity and access governance as AI adoption accelerates.
  • CISA Highlights Risks Around Unsupported Edge Devices
    CISA’s Binding Operational Directive 26-02 urges organizations to identify unsupported internet-facing infrastructure such as firewalls, routers, and VPN concentrators that no longer receive vendor patches or support. The directive reinforces the growing operational and compliance risks associated with end-of-support infrastructure and highlights the importance of modernization planning and vulnerability remediation.

Rubrik

Expanded Backup Controls and Large SQL Recovery Enhancements
Rubrik continues strengthening enterprise data protection capabilities with improvements focused on backup management, operational control, and large-scale SQL Server recovery support. The CDM 9.5.1 release also introduces storage optimization improvements and more granular workload administration.

View full Rubrik update
  • Rubrik CDM 9.5.1 Introduces Strict Window Enforcement
    CDM 9.5.1 adds the ability to automatically terminate snapshots and data transfer tasks that exceed configured backup windows when “Strict Window Enforcement” is enabled. This helps organizations reduce performance degradation caused by runaway backup operations and improve SLA compliance for production workloads.
  • Downloaded Snapshots No Longer Retained Indefinitely by Default
    Downloaded snapshots on Rubrik clusters now inherit retention periods defined by the associated SLA Domain rather than remaining permanently retained by default. The change helps reduce unnecessary storage consumption while improving retention policy alignment and operational consistency.
  • Granular Pause and Resume Controls Added for Scheduled Backups
    Administrators can now pause and resume scheduled backups for individual protected objects instead of pausing all backups for an entire cluster or SLA Domain. This provides greater operational flexibility for maintenance activities and troubleshooting while minimizing disruption to protected workloads.
  • SQL Server Backup Scale Expanded to 10,000 Files
    Rubrik CDM 9.5.1 now supports backup and recovery for Microsoft SQL Server databases containing up to 10,000 files, significantly increasing the previous limit of 800 files. The expanded scale applies to CBT-based incremental backups, log backups, archival workflows, recovery operations, and replication to clusters running CDM 9.4.1 or later, improving protection for large enterprise SQL environments.

Cohesity

Expanded SaaS Protection and SMB-Focused Data Resilience
Cohesity continues broadening workload coverage and simplifying enterprise-grade protection for organizations of all sizes. The latest updates expand Microsoft 365 workload support and improve Nutanix integration for backup and recovery.

View full Cohesity update
  • Cohesity 7.4 Adds Nutanix Files Protection
    Cohesity 7.4 introduces backup and recovery services for Nutanix Files clusters as NAS sources, including support for write-once-read-many (WORM) volumes. Organizations can protect multiple clusters through Prism Central integration or individual clusters through Prism Element integration, improving operational flexibility for Nutanix environments.
  • OneNote Backup and Recovery Support Added
    Cohesity 7.4 now supports backup and recovery of OneNote files stored in OneDrive, SharePoint, Teams, and Microsoft 365 Groups. This closes a previous data protection gap for Microsoft collaboration workloads, though administrators should expect the first backup after enabling the feature to take longer than normal.
  • Cohesity Essentials Targets Simplified SMB Protection
    Cohesity is positioning its Essentials offering as a simplified backup, recovery, and security platform designed to reduce operational complexity for SMB organizations. The approach delivers enterprise-grade data protection capabilities while lowering deployment and management overhead for smaller IT teams.

Nutanix

VMware Migration, AI Infrastructure, and NVMe Modernization
Nutanix is continuing to position its platform as a strategic modernization alternative for organizations reevaluating VMware licensing, AI infrastructure strategy, and traditional SAN architectures. The company is emphasizing hybrid cloud flexibility, infrastructure simplification, and software-defined operations.

View full Nutanix update
  • Nutanix and Microsoft Expand Azure VMware Migration Flexibility
    Nutanix and Microsoft now allow organizations to exchange existing Azure Reserved Instances, including Azure VMware Solution commitments, for Nutanix Cloud Clusters on Azure. The capability helps organizations reduce lock-in, optimize Azure spending, and transition VMware workloads into a more flexible hybrid cloud operating model.
  • Nutanix Emphasizes Unified Infrastructure for Production AI
    Nutanix highlighted that successful GenAI deployments require more than model access and instead depend on integrated infrastructure combining GPU-enabled compute, high-performance storage, cloud-native operations, and governance controls. The company continues positioning software-defined hybrid infrastructure as foundational for secure AI deployment and operational scalability.
  • NVMe/TCP Positioned as an Alternative to Fibre Channel SANs
    Nutanix is highlighting NVMe over TCP as a way to deliver NVMe-class performance over standard Ethernet networks without dedicated Fibre Channel infrastructure. Organizations evaluating external storage integration with Nutanix may benefit from lower infrastructure complexity while maintaining high-performance storage connectivity.

Everpure (Pure Storage)

File Workload Protection Expansion
Everpure continues enhancing cyber resilience and workload mobility for enterprise storage environments. The company’s latest updates expand synchronous replication and continuous access capabilities to file-based workloads.

View full Everpure (Pure Storage) update
  • ActiveCluster Adds Native File Workload Replication
    Everpure ActiveCluster now supports synchronous replication, transparent mobility, and continuous access for file-based workloads in addition to block-oriented datasets. Because the capability is built directly into the Purity operating system, organizations can extend resilience protections to file shares without requiring additional software or licensing.

Why It Matters: File services increasingly contain critical operational and unstructured AI data sets, making high-availability replication and ransomware resilience essential across both block and file workloads.


Nerdio

End-User Computing Modernization and Hybrid AVD Expansion
Nerdio continues expanding its management platform to support organizations modernizing virtual desktop infrastructure and Windows 365 deployments. The company is emphasizing migration planning flexibility and hybrid control plane management.

View full Nerdio update
  • Nerdio Compass Introduces VDI Discovery and Migration Planning
    Nerdio Compass provides discovery and planning capabilities designed to help organizations assess existing VDI environments and prepare migrations to Windows 365 or Azure Virtual Desktop. The initial private preview focuses on Citrix environments while future support is planned for Microsoft and VMware-based platforms.
  • Nerdio Manager for Enterprise 8.0 Expands Hybrid Support
    Nerdio Manager for Enterprise 8.0 adds enhanced Windows 365 management and introduces public preview support for Azure Virtual Desktop Hybrid on Nutanix Cloud Platform. This marks the first extension of Nerdio’s control plane beyond Azure and gives organizations more flexibility when modernizing end-user computing environments.

VMware

Lifecycle Deadlines and AI-Native Private Cloud Strategy
VMware and Broadcom continue emphasizing private cloud modernization, Kubernetes-native infrastructure, and AI-ready operations while customers face tightening lifecycle timelines for vSphere 8 environments.

View full VMware update
  • ESXi 8.0 Update 3i Delivers Security and Stability Updates
    VMware released ESXi 8.0 Update 3i in February 2026 with bug fixes and security updates for vSphere 8 environments. Organizations should also note that vSphere 8 reaches End of General Support on October 11, 2027, creating a narrowing timeline for upgrade, migration, and platform strategy planning.
  • VMware Cloud Foundation 9.1 Targets AI and Kubernetes Workloads
    Broadcom announced VMware Cloud Foundation 9.1 in May 2026 as an AI-native and Kubernetes-focused private cloud platform. The release introduces enhanced NVMe memory tiering, global vSAN deduplication, zero-trust security enhancements, and expanded automation intended to reduce infrastructure costs while supporting AI, containers, and traditional virtual machine workloads.

What’s New in Microsoft Cloud?

Azure

Azure: AI Expansion, Security Hardening, and Infrastructure Optimization

Microsoft continues accelerating Azure AI capabilities while expanding security controls, cost optimization tooling, and hybrid deployment flexibility. The latest updates span Azure Virtual Desktop, AKS, AI governance, storage optimization, and confidential computing.

  • Azure Virtual Desktop Hybrid Enters Public Preview
    Azure Virtual Desktop Hybrid now allows organizations to deploy virtual desktops on-premises while maintaining the Azure-hosted control plane with Microsoft Entra ID security integration. This provides organizations with additional deployment flexibility while preserving centralized identity, policy, and management capabilities.
  • Microsoft and OpenAI Restructure Strategic Partnership
    Microsoft and OpenAI revised their partnership structure by ending Azure exclusivity while maintaining Azure as the primary cloud and first-launch platform for OpenAI models through 2032. Azure customers retain priority access to frontier AI models while Microsoft continues expanding enterprise AI governance and deployment capabilities.
  • GPT-5.5 Reaches General Availability in Microsoft Foundry
    GPT-5.5 is now generally available in Microsoft Foundry, providing organizations with a governed deployment path for advanced reasoning models and agentic AI workflows. Enterprises can operationalize AI workloads without building custom machine learning infrastructure while maintaining centralized governance controls.
  • Smart Tier for Blob and Data Lake Storage Reaches GA
    The new Smart tier for Azure Blob and Data Lake Storage automatically moves data between hot, cool, and cold tiers based on access patterns. Microsoft reported that more than half of preview data automatically shifted to lower-cost storage tiers, helping organizations reduce storage spend without manual lifecycle management.
  • Azure Integrated HSM and FIPS 140-3 Protection Expand Globally
    Microsoft is open-sourcing Azure Integrated HSM and rolling out FIPS 140-3 Level 3 hardware-protected keys to V7 virtual machines globally at no additional cost. The enhancement strengthens workload security baselines and improves support for regulated workloads requiring advanced cryptographic protections.
  • Azure NetApp Files Adds Advanced Ransomware Protection
    Azure NetApp Files now includes Advanced Ransomware Protection with behavioral detection and automatic snapshots at no additional charge. The feature strengthens protection for enterprise file workloads against ransomware attacks and recovery events.
  • AKS April Release Expands GPU and Security Capabilities
    The April AKS release delivered ten generally available capabilities including H100 multi-instance GPU profiles, vertical pod autoscaling, managed control-plane protection, and simplified backup operations. Microsoft also issued an urgent kernel-level CVE mitigation that organizations should apply immediately to AKS Linux node pools.
  • New Intel Xeon 6 VM Family Reaches General Availability
    Azure’s new Dl/D/Esv7 general-purpose VM family reached GA with updated Intel Xeon 6 processors and built-in hardware key protection. The release provides improved price-performance for one of Azure’s most widely used VM categories.

Agent 365

Agent 365: Enterprise AI Governance and Security Controls

Microsoft is positioning Agent 365 as a centralized governance and security framework for enterprise AI agents. The platform extends Microsoft’s existing identity, compliance, and management stack into AI-driven workflows.

  • Agent 365 Reaches General Availability
    Microsoft Agent 365 is now generally available at $15 per user per month and extends governance, observability, and security controls for AI agents across Entra, Microsoft 365 Admin Center, Purview, Intune, and Defender. The offering helps organizations apply enterprise-grade oversight and policy enforcement to AI-driven automation and autonomous workflows.

Quick Take: AI agents are increasingly being treated as operational identities that require the same governance, monitoring, and compliance controls as human users and applications.

Copilot

Copilot: Consumption Pricing, Automation, and AI Governance Expansion

Microsoft continues rapidly expanding Copilot capabilities across productivity, automation, analytics, and AI governance. The latest updates introduce broader automation support, additional data grounding sources, enhanced administration controls, and more flexible licensing models.

Service Access

  • Copilot Services Transition to cloud.microsoft Domain
    Copilot services are moving to the cloud.microsoft domain and will require organizations to update network allow lists accordingly. Failure to update network policies may disrupt Copilot functionality and user access.

Models and Platform

  • Claude Sonnet Available Within Copilot Experiences
    Anthropic Claude Sonnet is now available in Copilot Chat and Word editing experiences with regional availability controls. Organizations gain additional model flexibility while maintaining administrative governance over model access.

User Experience and Surfaces

  • Copilot Cowork Adds Expanded Collaboration Features
    Copilot Cowork introduced mobile support, enterprise plugins, skills, and design enhancements as the platform moves closer to general availability. Licensing details remain unclear, so organizations should monitor future packaging and entitlement changes.
  • Copilot Navigation and Entry Points Are Being Standardized
    Microsoft is simplifying Copilot navigation across Microsoft 365 applications, including standardized right-side chat panes in Excel and updated Microsoft 365 app layouts. The changes are intended to create more consistent AI interaction patterns across workloads.
  • Files and Emails Can Be Opened Directly Within Copilot Chat
    Users can now open Outlook emails, Word documents, Excel files, PowerPoint presentations, and PDFs directly within Copilot chat experiences. The update streamlines workflow context switching and improves AI-assisted content interaction.
  • Forms Integrates Copilot and AI Agent Experiences
    Microsoft Forms now integrates Copilot Chat and a Forms/Surveys Agent that supports AI-assisted form creation, editing, invitation drafting, and response analysis. The capability reduces manual effort for survey and data collection workflows.
  • Copilot Action Discovery Expands to OneDrive and SharePoint
    Copilot action discovery is being surfaced in OneDrive and SharePoint file previews. This makes AI-assisted actions more discoverable in the context of file review and collaboration workflows.
  • PowerPoint Editing Supports Natural Language Prompts
    Copilot can now edit PowerPoint presentations using natural language prompts. This helps users accelerate presentation refinement while keeping editing workflows inside Microsoft 365.

Automation and Task Execution

  • Copilot Adds Calendar Agentic Automation
    Copilot can now automate calendar operations across Outlook and Teams using natural language prompts, including rescheduling meetings and personal events based on user preferences. The capability expands AI-driven workflow orchestration for collaboration workloads.
  • Agent Builder Adds Scheduled Prompt Execution
    Agent Builder now supports automatically scheduled prompts on hourly, daily, weekly, monthly, or yearly cadences without additional administrative setup. Users can manage recurring automation workflows directly within Copilot experiences.

Data Access and Grounding

  • Copilot Connectors Support Federated Data Access
    Copilot connectors now support federated access to internal and third-party data sources without requiring ingestion. This improves enterprise data access flexibility while potentially reducing data duplication and governance complexity.
  • Private Communities and Events Expand Grounding Sources
    Copilot can now use private community and event content as grounding sources. Organizations should evaluate whether these collaboration spaces contain sensitive or regulated data before broad enablement.
  • Outlook Shared and Delegated Mailboxes Are Supported
    Copilot now supports shared and delegated mailboxes in Outlook. This expands AI assistance to team-based mailbox workflows where access permissions, retention, and mailbox ownership should be reviewed.
  • Teams Meetings and Web Links Expand Grounding Sources
    Teams meetings and web links can now be used as grounding sources for Copilot interactions. Organizations should evaluate governance implications around meeting content exposure and AI-generated outputs.

Governance and Administration

  • Copilot License Request Workflows Expanded
    Enhanced Copilot license request capabilities now support custom approval workflows, business justification requirements, and centralized request pages. Organizations should establish governance processes before enabling broad self-service adoption.

Analytics and Optimization

  • Copilot Analytics and Usage Reporting Expand
    Microsoft expanded Copilot analytics with automatically generated dashboard summaries and exportable usage metrics across apps. This gives administrators better visibility into adoption patterns and optimization opportunities.
  • Copilot Chat Agent Usage Report Enters Preview
    A new Microsoft 365 admin center usage report for Copilot Chat agents provides visibility into active users, agents, and usage details segmented by license and creator type. General availability is expected at the end of July.
  • De-Identified Copilot Analytics Export Introduced
    Copilot Analytics is introducing a default-on, de-identified data export capability that provides weekly user-level usage metrics retained for six months. Organizations should review reporting access, privacy controls, and analytics governance before rollout.

Personalization

  • Copilot Memory and Personalization Expand
    Copilot personalization capabilities are being enhanced using chat history while maintaining user controls. Organizations should review governance, retention, and privacy implications associated with AI memory features.

What to Consider: Copilot adoption is increasingly shifting from experimentation to operational integration, making governance, approval workflows, data security, and analytics visibility critical.

Copilot Studio

Copilot Studio: Multi-Agent Orchestration and AI Development Controls

Microsoft continues evolving Copilot Studio into a broader enterprise AI orchestration platform with multi-agent collaboration, governance tooling, and real-time conversational capabilities.

  • Claude Sonnet 4.5 Retirement and Migration Timeline Announced
    Claude Sonnet 4.5 is retiring in Copilot Studio with automatic migration to version 4.6 unless organizations request a temporary extension. Customers receive 30 days to update agent models before Microsoft performs the automatic migration.
  • Real-Time Voice Agents Launch for Dynamics 365 Contact Center
    Real-time voice agents are launching within Dynamics 365 Contact Center to support adaptive conversational experiences for high-impact customer interactions. The capability is designed to operate within enterprise-grade governance and compliance controls.
  • Multi-Agent Collaboration Expands Across Fabric and Microsoft 365
    Copilot Studio agents can now collaborate with Fabric agents and Microsoft 365 Agents SDK agents to reuse business logic, orchestrate workflows, and reason across enterprise data. The approach helps organizations reduce duplication while improving AI workflow interoperability.
  • A2A Support Enables Cross-Agent Communication
    Copilot Studio now supports direct communication and task delegation between first-party, third-party, and external agents using open A2A protocols. This expands interoperability while increasing the importance of governance and identity controls for autonomous systems.
  • Immersive Prompt Builder Reaches General Availability
    The new Prompt Builder experience allows makers to edit prompts, switch models, configure inputs, and test changes directly within each agent’s Tools tab. The update simplifies agent development and operational management.
  • Content Moderation Controls Added for Prompt Management
    Copilot Studio introduced generally available prompt content moderation controls in supported regions. Organizations can now configure harmful content sensitivity thresholds for managed models to better align AI interactions with enterprise governance requirements.

Why It Matters: Enterprise AI environments are quickly evolving toward interconnected multi-agent ecosystems that require centralized governance, observability, identity controls, and lifecycle management.

Defender for Office 365

Defender for Office 365: Email Classification and Alert Noise Reduction

Defender for Office 365 continues improving message classification and analyst efficiency. The latest updates focus on promotional email handling and reducing alert fatigue without weakening investigation workflows.

  • Promotional Email Classification Expands
    Promotional email tagging and routing capabilities are being enhanced through automatic classification and learning behavior. The updates help improve inbox hygiene and reduce user exposure to unwanted or low-priority messaging.
  • Built-In Alert Tuning Rules Reach General Availability
    Defender alert tuning rules can now automatically suppress alerts tied to common benign activity in Defender for Office 365 without impacting AIR workflows or email notifications. The feature helps reduce analyst fatigue while preserving detection coverage.

Defender for Cloud

Defender for Cloud: Unified Visibility and Agent-Aware Security

Defender for Cloud is expanding its role within Microsoft’s unified security operations strategy. The latest updates connect cloud posture, Defender XDR workflows, and Agent 365 security insights.

  • Unified Security Console Integration Expands
    Defender for Cloud is being integrated more deeply into broader Defender XDR workflows to provide unified visibility across cloud security operations. This helps security teams correlate cloud risk with endpoint, identity, email, and agent telemetry.
  • Agent-Based Security Insights Added
    Defender for Cloud now incorporates agent-based security insights tied to the broader Defender ecosystem and Agent 365. This extends cloud security visibility into AI-driven workflows and helps organizations evaluate risk across both infrastructure and autonomous agents.

Defender XDR

Defender XDR: Advanced Hunting, Identity Paths, and AI Threat Detection

Defender XDR continues expanding unified detection and response capabilities across identity, endpoint, email, and AI agent activity. The latest updates improve analyst actionability, identity attack path visibility, Secure Boot readiness, and AI-aware runtime protection.

  • Advanced Hunting Adds Direct Enforcement Actions
    Defender XDR advanced hunting now supports direct allow or block actions for domains and email attachment hashes from within hunting query results. Analysts can respond to threats faster without leaving the investigation workflow.
  • Identity-Based Hunting Scenarios Added
    The hunting graph now includes predefined identity-focused attack path scenarios including Kerberoasting, AS-REP roasting, OAuth application risks, and domain compromise routes. Security teams can proactively identify privilege escalation and credential theft exposure.
  • Built-In Alert Tuning Rules Reach General Availability
    Defender alert tuning rules can now automatically suppress alerts tied to common benign activity in Defender for Endpoint without impacting AIR workflows or email notifications. The feature helps reduce analyst fatigue while preserving detection coverage.
  • Secure Boot Readiness Visibility Added
    Defender now provides Secure Boot readiness visibility and recommendations directly within the Defender portal. Organizations gain improved insight into endpoint hardening posture.
  • Defender for Agents Expands AI Security Operations
    Defender for Agents is now available with Agent 365 and provides posture management, runtime threat detection, tool-invocation blocking, and unified threat hunting across agent activity logs. The release reinforces Microsoft’s strategy of extending security operations into AI environments.

Edge for Business

Edge for Business: Cross-Tenant Protection and AI-Aware Browsing

Microsoft continues integrating security and AI-awareness directly into enterprise browser experiences.

  • Cross-Tenant Application Protection Added
    Edge for Business now supports cross-tenant application protection using Intune Mobile Application Management policies. The capability strengthens policy enforcement for organizations collaborating across tenants.
  • Copilot Search Relevance Uses Work Browsing History
    Copilot Search can now improve relevance using work browsing history when enabled through policy controls. Organizations should evaluate governance and privacy considerations before enabling the feature broadly.

Entra ID

Entra ID: Authentication Hardening and Identity Governance Expansion

Microsoft continues strengthening identity governance, passkey adoption, and federated authentication security within Entra ID.

  • Passkeys Reach General Availability on Windows
    Passkeys are now generally available on Windows and are expanding through registration campaigns. The move continues Microsoft’s push toward passwordless authentication and phishing-resistant identity controls.
  • Guest Governance Policy Changes Require Azure Subscription
    Organizations will now require an Azure subscription to modify guest governance policies. Administrators should review licensing impacts tied to external identity governance.
  • Federated Token Validation Defaults Becoming Stricter
    Microsoft will tighten federatedTokenValidationPolicy defaults beginning in mid-August 2026, blocking federated sign-ins when internalDomainFederation values do not match the user UPN domain. Organizations should validate federation configurations before enforcement begins.
  • Cross-Tenant Group Synchronization Expands Collaboration Controls
    Cross-tenant group synchronization is now available to simplify collaboration and centralized group management across tenants. The feature improves identity consistency for multi-organization environments.
  • Account Discovery Helps Identify Orphaned Identities
    Account discovery capabilities are now available to identify unmanaged or orphaned accounts that may introduce security and governance risk.
  • Authentication Methods Policy Logs Reduce Noise
    Authentication Methods Policy logs now display only changed values, improving audit clarity and simplifying troubleshooting.
  • Entra Connect Blocks Hard-Match Sync for Privileged Accounts
    Entra Connect will now block hard-match synchronization for privileged accounts to reduce the risk of account takeover scenarios.

Exchange Server

Exchange: Hybrid Modernization and Legacy Protocol Retirement

Microsoft continues modernizing Exchange connectivity while tightening security requirements for legacy protocols.

  • Exchange Server SE Hotfix Adds Graph-Based Hybrid Migration Support
    Microsoft released a Hotfix Update for Exchange Server Subscription Edition that enables migration of hybrid rich coexistence workflows from Exchange Web Services to REST-based Microsoft Graph APIs. The change supports Microsoft’s ongoing transition away from legacy EWS-based integrations.
  • Exchange Server 2016 and 2019 ESU Coverage Extended
    Microsoft announced Extended Security Update Period 2 for Exchange Server 2016 and 2019, extending paid security-only support through October 31, 2026. Organizations still running on-premises Exchange should continue modernization planning before support deadlines tighten further.
  • Exchange Online Blocks TLS 1.0 and 1.1 Starting July 2026
    Exchange Online will block POP3 and IMAP4 connections using TLS 1.0 or 1.1 beginning in July 2026. Organizations relying on legacy printers, embedded devices, or older mail clients must migrate to TLS 1.2 or newer to avoid connectivity failures.

Fabric

Fabric: AI, Real-Time Analytics, and Data Engineering Enhancements

Microsoft Fabric continues expanding enterprise analytics, streaming, AI integration, and developer productivity capabilities across the unified data platform.

  • Tabbed Multitasking and Object Explorer Reach GA
    Fabric’s tabbed multitasking and object explorer experiences are now generally available following extensive preview feedback and performance tuning. The enhancements improve navigation and workflow efficiency for analytics teams.
  • Semantic Model Auto-Description Introduced in Preview
    Fabric now supports AI-generated descriptions for semantic models to improve discoverability and understanding of enterprise data assets.
  • Netezza ODBC Driver Deprecation Begins
    Microsoft is beginning deprecation of the previously built-in Netezza ODBC driver in favor of the newer generally available IBM driver.
  • Notebook Retry Policies Improve Job Resilience
    Fabric Notebook now supports retry policies that automatically restart jobs following system errors. This improves workload resiliency for long-running data engineering processes.
  • VS Code Integration Expands Across Fabric Workloads
    The Fabric Data Engineering VS Code extension now supports workspace management, Environment editing, and Lakehouse configuration directly within Visual Studio Code.
  • Maven Support Added for Fabric Environment Preview
    Fabric Environment preview now supports Maven repositories, simplifying dependency management for Scala and Java development workloads.
  • Cross-Workspace MLflow Support Expands MLOps Flexibility
    Fabric now supports cross-workspace MLflow logging for machine learning experiments and models, enabling more consistent promotion pipelines from development through production.
  • SemPy 0.14.0 Adds 75 Admin APIs
    SemPy 0.14.0 introduces extensive tenant administration APIs covering workspaces, reports, capacities, users, and tenant settings directly from Python.
  • JSONL COPY INTO Support Added
    Fabric Data Warehouse now supports direct ingestion of newline-delimited JSON files using COPY INTO operations.
  • Eventstream and Eventhouse Real-Time Intelligence Expands
    Fabric introduced expanded Eventstream observability, schema evolution support, MCP integration for AI agents, direct Activator rule management, and mTLS connector support. These capabilities improve real-time analytics, streaming governance, and AI integration.

Intune

Intune: Hotpatching, MAM Expansion, and Administrative Improvements

Microsoft continues reducing endpoint management friction through expanded hotpatching, broader mobile application management coverage, and improved administrative experiences.

  • Hotpatching Enabled by Default
    Windows Autopatch now enables hotpatch updates by default, reducing reboot frequency and accelerating patch deployment. Organizations can also globally opt out using new tenant-level controls.
  • Additional Applications Added to Intune MAM Portfolio
    Intune expanded its protected application portfolio to include applications such as DeepL and Foxit PDF Editor, extending mobile application protection coverage.
  • Support Assistant Expanded to Authenticated Users
    Support Assistant is now available to all authenticated admin center users, though appropriate roles are still required for ticket creation.
  • Multiple Managed Mobile Accounts Supported
    Mobile applications now support multiple managed accounts with per-account protection policies. This improves flexibility for organizations managing complex user access scenarios.
  • Apple Integration Requires Updated Terms Acceptance
    Organizations using Apple integrations must accept updated terms to maintain functionality.

Loop

Loop: Workspace Governance Controls

Microsoft continues tightening governance around collaborative Loop experiences.

  • Loop Workspace Creation Can Be Restricted
    Administrators can now restrict Loop workspace creation to existing Microsoft 365 Groups. The capability improves governance and reduces uncontrolled collaboration sprawl.

Quick Take: Collaboration governance is becoming increasingly important as AI and shared workspaces intersect across Microsoft 365.

Microsoft 365 Apps

Microsoft 365 Apps: Lifecycle Planning and Update Visibility

Microsoft is continuing lifecycle modernization efforts while improving update health reporting.

  • Office LTSC 2021 Support Ends in October 2026
    Microsoft confirmed that Office LTSC 2021 support ends on October 13, 2026. Organizations still relying on perpetual Office deployments should begin migration planning.
  • Cloud Update Health Reporting Added
    Microsoft 365 Apps is introducing enhanced cloud update health reporting to improve update diagnostics and deployment visibility.

What to Consider: Organizations should accelerate Microsoft 365 Apps lifecycle planning to avoid support gaps and improve update management visibility.

OneDrive

OneDrive: Scalability and Offboarding Improvements

Microsoft continues improving OneDrive scalability and user lifecycle management.

  • OneDrive Sync Capacity Expands to One Million Items
    OneDrive Sync now supports up to one million items per device in preview. The update helps organizations managing increasingly large collaboration datasets.
  • Offboarding File Transfer Experience Improved
    Microsoft is enhancing OneDrive’s offboarding transfer experience for departing users to simplify data handoff and retention workflows.

Outlook

Outlook: AI Assistance and Collaboration Enhancements

Microsoft continues modernizing Outlook collaboration and accessibility experiences.

  • Voice-Based Inbox Management Introduced
    Outlook now supports voice-driven inbox management for hands-free email triage and workflow interaction.
  • Account Manager Experience Updated
    A new Account Manager experience introduces profile pictures, improved account switching, and simplified access to account details.
  • People Hub Redesign Expands Contact Visibility
    Outlook’s People Hub is being redesigned with enriched contacts and improved search capabilities.
  • Tenant-Wide Recipient Separator Policy Added
    Administrators can now define tenant-wide default recipient separator behavior using commas.
  • Support for Sending Local Files as Attachments Expands
    Outlook will support attaching locally stored Word, Excel, and PowerPoint files beginning in September.
  • Follow Without Attending Added
    Users can now follow meetings without formally attending them.
  • Shared Calendars Move to Modern REST Model
    Shared calendars are being upgraded to Microsoft’s modern REST-based architecture.

Quick Take: Outlook modernization continues emphasizing accessibility, collaboration flexibility, and consistency with Microsoft’s broader Graph-based architecture strategy.

Planner

Planner: Expanded Teams Integration

Microsoft continues integrating Planner more deeply within Teams collaboration workflows.

  • Planner Tabs Expand to Shared and Private Channels
    Planner tabs are now supported in shared and private Teams channels, improving task visibility and coordination across collaboration scenarios.

Why It Matters: Project management and collaboration experiences continue converging directly inside Teams workspaces.

Power BI

Power BI: Mobile Copilot and Web Modeling Enhancements

Power BI is introducing lightweight but meaningful updates focused on mobile interaction and developer-centric modeling experiences.

  • Copilot chat in Power BI mobile (Preview)
    Users can now interact with Copilot directly inside reports on the Power BI mobile app. This enables on-the-go data exploration using natural language, improving accessibility to insights without requiring desktop access.
  • TMDL View on the Web
    TMDL View will soon be available in the browser, enabling a code-first semantic modeling experience without needing desktop tools. This gives developers more flexibility to build and manage models directly in web environments. 

Power Platform

Power Apps and Dataverse — AI Governance, Recovery, and Agent Identity Controls

Power Apps and Dataverse updates focus on AI governance, agent identity, app runtime behavior, audit controls, and recovery posture. These changes help administrators improve oversight of autonomous agents while aligning app data, access, and recovery practices with enterprise requirements.

  • Agent Feed Adds Real-Time Monitoring Capabilities
    Power Platform now includes an Agent feed experience for real-time monitoring and management of autonomous agents. This gives administrators and makers more visibility into agent behavior and helps support operational control for AI-driven workflows.
  • Copilot Hub Adds Additional Administrative Controls
    Microsoft expanded administrative governance controls for AI features within Copilot hub. These controls help organizations manage AI feature availability and reduce the risk of unmanaged adoption across Power Platform environments.
  • Canvas Apps Online Mode Added
    Online mode is now available for Canvas apps. This expands runtime flexibility for app experiences and gives makers additional options when designing business applications.
  • Audit Log Data Removal Supported
    Organizations can now remove customer data from audit logs when required. This may support privacy, compliance, or data governance requirements where audit data contains sensitive customer information.
  • Backup Retention Reduced from 28 Days to 7 Days
    Power Platform backup retention is being reduced from 28 days to 7 days, though deleted records remain recoverable. Organizations should review disaster recovery, retention, and restore procedures to ensure recovery expectations still align with business and compliance requirements.
  • Agent Lifecycle APIs and Registry Changes Announced
    Microsoft is retiring Agent Registry APIs while introducing Agent 365 APIs as part of evolving AI governance architecture. Organizations using agent lifecycle integrations should plan API updates to avoid operational disruption.
  • Self-Service Disaster Recovery No Longer Requires PAYG
    Organizations can now use self-service disaster recovery without requiring Pay-As-You-Go billing. This reduces adoption friction for recovery capabilities and may improve resilience planning across Power Platform environments.
  • Dataverse Adds Agent Users with Entra Agent ID
    Power Apps and Dataverse now support agent identities powered by Microsoft Entra Agent ID, allowing administrators to assign roles, audit activity, and govern AI agents as managed identities. This strengthens accountability and access control for autonomous agent activity inside Dataverse.
Power Automate — Automation Governance and Flow Testing Enhancements

Power Automate updates focus on improving automation governance, testing, and change visibility for desktop flow development. These enhancements help makers validate changes more confidently and improve reliability for reusable automation components.

  • Power Automate Adds Desktop Flow Comparison Tools
    Power Automate now supports side-by-side desktop flow version comparison for improved troubleshooting and governance. This helps makers and administrators understand automation changes before deployment or rollback.
  • Desktop Flow Testing Expands to Subflows
    Power Automate desktop testing now supports test creation and assertions for subflows to improve automation reliability. Makers can define inputs, expected outputs, and assertions at the child-flow level, helping teams validate reusable automation components before production use.

Purview

Purview: AI Governance, Retention Expansion, and Data Protection Controls

Microsoft continues expanding Purview’s role as the governance and compliance foundation for AI, collaboration, and data protection workloads.

  • eDiscovery Naming Rules Tightened
    Purview eDiscovery naming rules are being updated to restrict special characters and improve consistency.
  • Retention Policies Expand to Teams Call Logs
    Purview Data Lifecycle Management will now support retention and deletion policies for Teams call logs.
  • Endpoint DLP Diagnostics Enabled by Default
    Endpoint DLP diagnostics are now enabled by default to improve visibility into policy activity and enforcement outcomes.
  • OCR Support Added to Data Security Investigations
    Data Security Investigations is adding OCR support by mid-2026 to improve analysis of image-based sensitive content.
  • Purview for Agents Reaches General Availability
    Purview for agents is now generally available with AI observability and insider risk management capabilities.
  • Expanded Governance for Agent 365 Announced
    Microsoft announced broader Purview protections for Agent 365, reinforcing governance, compliance, and audit requirements for AI agents.
  • Sensitivity Labels Can Restrict Connected Experiences
    Organizations can now use sensitivity labels to block connected experiences that analyze content.
  • Copilot Web Search Restrictions Added in Preview
    New preview capabilities can prevent Copilot from using external web search when prompts contain sensitive data, reducing the risk of data leakage.
  • Whiteboard Content Added to eDiscovery Visibility
    Whiteboard content can now be viewed directly inside eDiscovery workflows.
  • Data Governance Enhancements Expand Across Unified Catalog
    Purview Data Governance updates include glossary migration, bulk editing, advanced resource sets, and expanded data product capabilities.

SharePoint Online

SharePoint Online: AI-Powered Experiences and Legacy Governance Retirement

Microsoft continues transforming SharePoint into an AI-enabled collaboration platform while retiring older governance and workflow technologies.

  • Legacy Information Management Features Retired
    Microsoft retired SharePoint Information Management Policies, In-Place Records Management, and deletion-only policies across SharePoint Online. Organizations must migrate to Purview Data Lifecycle Management and Records Management for compliance and retention operations.
  • Copilot-Powered Page Creation and Editing Introduced
    SharePoint now supports AI-assisted page creation and editing experiences powered by Copilot.
  • AI-Powered SharePoint Site Experience Launches
    Microsoft launched a new SharePoint site experience featuring Copilot-driven content discovery and navigation. SharePoint sites are increasingly positioned as active AI-enabled workspaces rather than passive content repositories.
  • AI Charts Web Part Added
    SharePoint introduced an AI-driven charts web part that generates visualizations using natural language prompts.
  • SharePoint Designer 2013 and InfoPath Retirement Scheduled
    SharePoint Designer 2013 and InfoPath will retire in July 2026, requiring organizations to modernize legacy forms and workflow solutions.
  • AI Citation Analytics Added
    SharePoint is introducing AI citation analytics to help organizations understand how Copilot uses content.
  • Home Site Experience Modernized
    Home sites are receiving updated setup experiences, new Resources and Announcements web parts, and expanded customization aligned with the renamed SharePoint app in Teams.
  • News Web Part Adds Filmstrip Layout
    SharePoint News now supports a Filmstrip layout and expanded multi-site aggregation capabilities.
  • SPO One-Time Passcode Authentication Retiring
    SharePoint Online One-Time Passcode authentication retires by August 31, requiring external users to use Entra B2B guest accounts. The change improves Conditional Access enforcement and guest governance visibility.

SharePoint Server

SharePoint Server: Security Updates and Patch Prerequisites

Microsoft continues maintaining SharePoint Server security while organizations plan long-term modernization.

  • April 2026 Public Update Addresses Multiple Vulnerabilities
    Microsoft released April 2026 SharePoint Server updates addressing spoofing vulnerabilities CVE-2026-20945 and CVE-2026-32201 along with remote code execution vulnerabilities affecting Office Online Server.
  • Prerequisite PowerShell Script Required Before Installing Updates
    Organizations patched to the September 2025 Cumulative Update must run Fix-SeptemberCU-Permission-Problem.ps1 before applying the April 2026 updates. Failure to complete the prerequisite step will cause installation failures.

Teams

Teams Chat & Channels — Workflow Simplification and Agent Interactions

Microsoft continues streamlining Teams collaboration while introducing deeper AI agent integration.

  • Targeted Agent Messages Added to Teams
    Teams now supports targeted temporary messages from agents and bots that can be sent privately within channels, meetings, or group chats without notifying all participants. The capability reduces notification fatigue while enabling more contextual AI interactions.
  • Threaded Conversations Become Default in New Channels
    Threaded conversations are now the default experience for new Teams channels.
  • Teams App Bar and Navigation Simplified
    Microsoft simplified the Teams app bar by hiding labels by default and improving quick access to unread mentions and followed threads.
  • Compliance Shifts Toward Group-Based Enforcement
    Teams compliance enforcement is increasingly moving toward group-based governance models.
  • Muted and Meeting Chat Sections Added
    Teams now automatically organizes muted chats and meeting chats into dedicated sections to reduce clutter.
  • Workflow Slash Commands Added to Chat
    Users can now create workflows directly from Teams chat using slash commands.

Quick Take: Teams is evolving toward a more AI-assisted collaboration model while reducing user interface complexity and improving governance flexibility.

Teams Meetings — AI Translation, Recaps, and Meeting Governance

Microsoft continues embedding AI-driven accessibility, transcription, and meeting intelligence into Teams conferencing.

  • Real-Time Translation Reaches General Availability
    Real-time translation with automatic language detection is now generally available in Teams meetings. The capability supports multilingual collaboration without requiring manual participant configuration.
  • CSV-Based Breakout Room Assignment Added
    Teams now supports breakout room assignment through CSV import.
  • Interpreter Agent Public Preview Expands Consecutive Interpretation
    The Interpreter agent entered public preview and visually appears on the meeting stage during bilingual meetings.
  • AI Meeting Recap Features Expanded
    Teams is adding recap support without transcripts, recap deletion capabilities, and more granular recap access controls.
  • Loop-Powered Meeting Notes Expand to Instant Meetings
    Microsoft Loop meeting notes are now available for Meet Now and chat-based instant meetings with Planner and To Do integration.
  • External Bots Will Be Clearly Labeled in Meetings
    Teams will begin labeling external bots entering meetings beginning in May 2026 so organizers can approve or reject AI transcription and meeting assistant tools.
  • Meeting Transcription and Annotation Capabilities Expand
    Teams is adding auto-start transcription, transcription-only mode, participant-requested annotation support, and macOS annotation improvements.
  • SIP Join Support Expands Multivendor Interoperability
    Teams is improving meeting join experiences by expanding SIP join support for multivendor conferencing.
  • Audio Device Testing Added Pre-Join
    Users can now test audio devices before joining Teams meetings.
  • Together Mode Retirement Announced
    Microsoft is retiring Together mode.

Why It Matters: AI meeting intelligence and translation capabilities are becoming operational collaboration tools that require stronger governance, meeting security visibility, and retention oversight.

Teams Rooms — Cross-Platform Collaboration and Meeting Experience Enhancements

Microsoft continues modernizing Teams Rooms experiences across Windows, Android, and VDI environments.

  • Minimized Meeting Experience Introduced
    Teams Rooms users can now raise hands and send reactions while meetings are minimized.
  • VDI Optimization Expanded for Omnissa Horizon and Workspace ONE
    Microsoft is replacing WebRTC-based VDI optimization with a dedicated media engine aligned with native Teams clients.
  • Miracast Wireless Sharing Added to Teams Rooms on Windows
    Teams Rooms on Windows Pro now supports Miracast wireless content sharing.
  • Cross-Platform SIP Join Added to Teams Rooms on Android
    Teams Rooms on Android now supports enhanced SIP join functionality for multivendor meeting interoperability.
  • Panel Devices Add Future Meeting Booking
    Android-based Teams panels can now book future meetings directly from the panel after administrative activation.
Teams Phone — Fraud Protection and Expanded Calling Flexibility

Microsoft continues modernizing Teams Phone with expanded call handling and fraud prevention features.

  • Multi-Line Support Expands to 10 Numbers Per User
    Teams Phone now supports up to 10 numbers per user for advanced calling scenarios.
  • Brand Impersonation Protection Added
    Teams Calling is introducing warnings for suspicious inbound calls from first-contact external callers to reduce fraud and impersonation risks.
  • Mobile Queues App Introduced
    Microsoft released a Mobile Queues app for managing call queues from mobile devices.
  • Call Transfer Experience Improved
    Teams Phone is updating transfer workflows to improve usability.

Quick Take: Voice collaboration security and mobile-first administration capabilities continue expanding as Teams Phone adoption grows.

Teams Premium — AI-Powered Interpretation Expansion

Microsoft continues expanding premium AI-assisted meeting capabilities.

  • AI-Powered Live Interpretation Added to Teams Phone Devices
    Teams Premium now supports AI-powered live interpretation directly on Teams Phone devices.

Why It Matters: AI translation and interpretation are quickly becoming standard enterprise collaboration requirements for global organizations.

Teams — Performance Optimization and UI Modernization

Microsoft continues simplifying Teams while improving performance and retiring legacy integration models.

  • Teams Interface and App Bar Simplification Continues
    Microsoft is streamlining Teams navigation and app bar experiences to reduce workspace clutter.
  • Efficiency Mode Added for Performance Improvements
    Teams is introducing Efficiency mode to improve client performance and resource utilization.
  • Customer Connect Replaces Live Chat
    Customer Connect replaces Live Chat and introduces booking capabilities.
  • Office 365 Connectors Retirement Requires Migration
    Organizations must migrate away from retiring Office 365 connectors used within Teams.

What to Consider: Teams governance and integration modernization should include connector migration planning and evaluation of new AI-assisted collaboration workflows.

Windows

Windows: Secure Boot Hardening and In-Place Upgrade Modernization

Microsoft continues strengthening endpoint security and simplifying Windows Server modernization workflows.

  • April 2026 Patch Tuesday Expands Secure Boot Visibility
    KB5083769 for Windows 11 adds Secure Boot certificate update status visibility, expands support for newer Secure Boot certificates, and resolves an issue that pushed some systems into BitLocker Recovery.
  • Remote Desktop Phishing Protection Added
    Windows now displays connection settings embedded within .rdp files before sessions begin and introduces one-time security warnings for first use.
  • Vulnerable Driver Blocklist Updates May Affect Backup Software
    KB5083769 updates the vulnerable driver blocklist and may cause VSS timeout errors for backup applications relying on blocked kernel drivers.
  • Kerberos Security Hardening Continues
    Microsoft continues rolling out additional Kerberos hardening protections across Windows environments.
  • Windows Server 2025 In-Place Upgrades Supported Through Windows Update
    Organizations can now upgrade Windows Server 2019 and 2022 systems directly to Windows Server 2025 using Windows Update without installation media..

 

Windows 365

Windows 365: Break-Glass Cloud PC Availability

Microsoft continues expanding business continuity options for Cloud PC deployments.

  • Windows 365 Reserve Announced
    Windows 365 Reserve introduces low-cost emergency Cloud PCs that can be activated for up to 10 days annually for approximately $20 per year. The capability provides organizations with a break-glass continuity option during outages or endpoint disruption events.

Get in Touch with Us

Connect with an expert to learn what we can do for your business.

Request Access to Win Wires

Enter your work email to request access to the eGroup Win Wires repository.

By requesting access, you confirm you are using an approved business email domain. You’ll receive a secure, one-time login link after returning to the Win Wires page.