Enterprise IT teams have a busy August ahead, with critical infrastructure security fixes, AI governance changes, major Microsoft 365 administration shifts, and several approaching retirement deadlines. This month’s updates put particular emphasis on securing AI agents, modernizing identity and data protection controls, validating recovery and resilience plans, and preparing now for platform changes that could create operational disruption if left until their enforcement dates.
What’s the Buzz at eGroup This Month?
Get More Value from Microsoft with the CSP Advantage Program
eGroup’s new Microsoft CSP Advantage Program is designed to help organizations get more from their Microsoft investments with added guidance, support, and expertise around the technologies they already own. It gives IT teams a more strategic way to manage their Microsoft environment while simplifying operations and identifying opportunities to improve value across the business.
ThreatDefender MXDR Gets Smarter with SARA
ThreatDefender MXDR is now enhanced with SARA, eGroup’s AI-powered Security Analysis & Response Agent. SARA strengthens the managed detection and response experience by helping accelerate security analysis and response, giving teams additional support for identifying threats, understanding risk, and acting faster when incidents occur.
eGroup Named No. 134 on CRN’s 2026 Solution Provider 500 Fast Growth List
eGroup was named to the No. 134 spot on CRN’s 2026 Solution Provider 500 Fast Growth List. The recognition highlights solution providers that combine significant market scale with continued business growth, reflecting both eGroup’s momentum and its commitment to helping clients get more value from their technology investments.
Together, these updates reflect a continued focus on helping organizations make technology easier to manage, more secure, and more valuable, whether that means optimizing Microsoft investments, strengthening day-to-day security operations, or modernizing the broader IT environment.

What’s New in the Hybrid Data Center?
Cisco
Critical IOS XE Fixes and a New Catalyst Baseline
Cisco’s August updates focus on significant IOS XE security remediation and a new software baseline for Meraki-managed Catalyst environments. Infrastructure teams should prioritize vulnerability remediation while carefully planning cloud-management migrations that cannot be reversed through Dashboard.
View full Cisco update
- Seven IOS XE Vulnerabilities Remediated. Cisco’s August 5, 2026 release addresses seven IOS XE vulnerabilities affecting devices operating in autonomous or controller mode. One vulnerability carries a CVSS score of 9.8, another is rated 9.0, and the remaining five are rated 8.6; Cisco reported that the issues were discovered through internal testing and were not known to be actively exploited at disclosure.
- IOS XE 17.18.4 Reaches GA for Meraki-Managed Catalyst. Cisco made IOS XE 17.18.4 generally available on August 5 for the Meraki-managed Catalyst switching path, including the August security-hardening fixes and making it the immediate baseline for cloud-managed Catalyst deployments. Moving to Cloud Management with IOS XE cannot be reversed to prior CS firmware through Dashboard, so organizations should validate migration plans, operational requirements, and rollback assumptions before making the transition.
Rubrik
More Efficient VMware Cloud Vault Retention
Rubrik is improving the storage efficiency and recoverability of VMware backups archived to Rubrik Cloud Vault. The change is designed to reduce cloud storage consumption, while shortening the dependency chain involved in recovering incremental data.
View full Rubrik update
- Rubrik Cloud Vault Adds Optimized Snapshot Retention for VMware. Starting with Rubrik CDM 9.5.2, Rubrik Cloud Vault archival locations protecting VMware data use Rubrik Optimized Snapshot Retention technology. The change is designed to reduce cloud-storage consumption while accelerating recovery for protected VMware workloads.
- Periodic Full Backups Shorten Incremental Chains. Rubrik improves its incrementals-forever approach by periodically creating full backups that serve as the basis for subsequent incremental chains. This reduces the number of previous backups on which each incremental depends and allows storage consumed by older incremental backups to be reclaimed more quickly.
Why It Matters: Organizations with large VMware retention footprints in RCV may see both capacity and recovery benefits, making CDM 9.5.2 particularly relevant when cloud-storage growth or recovery-chain complexity is becoming a concern.
Cohesity
Broader Microsoft, Azure, and Object Recovery Coverage
Cohesity 7.4.1 expands protection across Microsoft 365, Azure, VMware, Cosmos DB, and S3-based workloads. The release also makes backup selection and object-level recovery more practical for environments managing large numbers of users and cloud workloads.
View full Cohesity update
- OneNote Backup Expands Across Microsoft 365. Cohesity 7.4.1 adds backup support for OneNote files across SharePoint, Teams, OneDrive, and Microsoft 365 Groups. Organizations relying on OneNote content within collaborative workloads can therefore bring those files into their broader protection and recovery strategy.
- Entra Security Groups Can Drive OneDrive and Mailbox Protection. Administrators can now select all users in an Entra ID security group as a group when configuring OneDrive and mailbox backup instead of selecting users individually. This reduces administrative overhead and helps align backup scope with identity-based group membership as users join, leave, or move between organizational groups.
- SharePoint Online Site Pages Can Be Backed Up. Cohesity 7.4.1 adds backup support for SharePoint Online site pages. This broadens recoverable SharePoint content and should be factored into organizations’ collaboration-data protection and restoration procedures.
- AVS VMs Gain Additional Datastore Support. Cohesity can now protect Azure VMware Solution virtual machines whose datastores reside on Azure NetApp Files and Pure Cloud Block Store. This expands supported AVS storage architectures and gives organizations additional flexibility when standardizing backup across hybrid VMware deployments.
- Primary Backups Can Land Directly on Azure Archive and Cold Tiers. Cohesity Cloud Edition on Azure supports creating primary copies of Azure VM, VMware VM, and Azure-based NAS backups directly on the Archive and Cold tiers of Azure Blob Storage. The release also adds database-level backup for Cosmos DB for MongoDB and Cosmos DB for NoSQL, expanding the range of cloud-native workloads that can be protected with workload-aware recovery options.
- S3 Views Gain Indexing and Object-Level Recovery. Cohesity SmartFiles now supports indexing S3 Views, enabling object-level recovery of S3 content along with searching and browsing S3 View snapshots. This can materially improve recovery precision for teams that need to locate individual objects rather than restore entire snapshots.
Quick Take: Cohesity 7.4.1 is primarily a coverage and recoverability release, but its Entra group-based selection and direct-to-Archive or Cold options may also reduce operational effort and storage-management complexity.
Nutanix
AI Agent Automation Meets Infrastructure Governance
Nutanix is extending its hybrid cloud management platform to AI agents while continuing to push customers toward its current AOS lifecycle. The new MCP capability is particularly notable because it brings natural-language infrastructure automation under existing Nutanix governance controls.
View full Nutanix update
- Nutanix Launches an Open-Source MCP Server. On August 10, Nutanix announced a Model Context Protocol server for Nutanix Cloud Platform that allows AI agents such as GitHub Copilot, Claude Code, and Cursor to translate natural-language requests into Prism v4 API actions across hybrid cloud environments. The open-source server enforces Nutanix RBAC, throttling, auditing, and asynchronous task controls, allowing infrastructure teams to introduce agent-based automation without rebuilding their established governance mechanisms.
- AOS 7.6 Remains the Strategic Upgrade Target. AOS 7.6 is the latest major release, with end of maintenance scheduled for October 31, 2027, and end of support scheduled for July 31, 2028. AOS 7.5 and 7.3 both received maintenance patches on July 28 that extend their supported lifecycles, but organizations should continue planning toward AOS 7.6 and prioritize moving remaining 6.x environments forward.
Nerdio
Easier Movement Between AVD and Windows 365
Nerdio is making it easier for organizations to reconsider how personal desktops are delivered across Microsoft’s virtual desktop platforms. The new migration capability can support both strategic transitions and targeted workload placement decisions.
View full Nerdio update
- Nerdio Manager for Enterprise 8.1.1 Reaches GA. Nerdio Manager for Enterprise 8.1.1 became generally available on August 4. The release expands desktop migration capabilities for organizations managing both Azure Virtual Desktop and Windows 365 environments.
- AVD Personal Desktops Can Move to Windows 365 Flex Dedicated. The release adds single and bulk migration support for moving Azure Virtual Desktop Personal desktops to Windows 365 Flex Dedicated. This gives organizations a more direct way to choose between, or transition workloads across, AVD and Windows 365 based on operational and user requirements.
What to Consider: Review existing AVD Personal populations for workloads that may benefit from Windows 365 Flex Dedicated, but evaluate management, licensing, user experience, and cost before treating migration as a purely technical exercise.
VMware
Critical VMSA Requires Patch Planning
Broadcom’s latest VMware advisory spans multiple products across the VMware infrastructure stack. With severity reaching CVSS 9.8 and no workaround for the most serious issues, remediation should be treated as a priority.
View full VMware update
- VMSA-2026-0006 Covers Five VMware Vulnerabilities. Broadcom issued VMSA-2026-0006 on July 29 covering five vulnerabilities across vCenter, ESX/ESXi, Workstation, Fusion, VMware Cloud Foundation, and vSphere Foundation. The broad product scope means organizations should review exposure across both server and endpoint VMware environments.
- Severity Reaches CVSS 9.8 With No Workaround for the Most Serious Issues. The advisory includes vulnerabilities rated as high as CVSS 9.8, and Broadcom provides no workaround for the most serious issues. Affected organizations should move directly to assessing applicable patches, maintenance windows, and remediation priorities.

What’s New in Microsoft Cloud?
Azure
Azure: Production AI, Security, Resilience, and Platform Governance
Azure’s August updates show Microsoft continuing to turn enterprise AI from experimentation into an operational platform. The changes span model availability, agent governance, observability, networking, resilience testing, Kubernetes security, and the formalization of Azure Landing Zone engineering.
- GPT-5.6 and Production Agent Capabilities Reach Microsoft Foundry. GPT-5.6 is generally available in Microsoft Foundry alongside new production capabilities in Foundry Agent Service. Organizations can use stronger reasoning models to build agents under Azure enterprise security and compliance controls and publish those agents into experiences such as Microsoft Teams and Microsoft 365 Copilot.
- Azure API Management Adds an AI Gateway Tier. A public preview AI Gateway tier is designed specifically for AI workloads and gives teams a consistent way to expose and manage AI models, tools, and agent connections. It supports security, authentication, policies, and observability across models hosted in Microsoft Foundry, AWS Bedrock, Google Vertex AI, OpenAI, and Anthropic, helping organizations create a governance layer across heterogeneous AI platforms.
- Cobalt 200 Arm-Based VMs Enter Early Access Preview. Cobalt 200 Arm-based virtual machines designed for Linux agentic AI workloads are now in early access preview. Organizations evaluating Linux-based AI agent infrastructure can begin assessing whether Arm-based compute fits their performance, compatibility, and cost requirements.
- Microsoft Discovery Reaches General Availability. Microsoft Discovery, a platform for building and governing agentic AI workflows, is now generally available. Its GA status gives enterprises another Microsoft-managed option for moving governed agent workflows into production.
- Azure Landing Zone Becomes an Official Microsoft Product. Azure Landing Zone has transitioned from a community open-source initiative into an official Microsoft product with a dedicated engineering team and roadmap. Organizations that use Landing Zones as a cloud-governance foundation should account for the change in their architecture and lifecycle planning.
- Application Insights Separates Sensitive Generative AI Telemetry. Azure Monitor Application Insights now stores generative AI content in a dedicated table with access controls that can restrict visibility into prompts, responses, tool calls, and other AI-generated telemetry. Because observability data can itself contain sensitive or regulated information, security and compliance teams should explicitly review access to this telemetry rather than treating it like ordinary application diagnostics.
- Azure Monitor Logs Can Mirror into Fabric. Azure Monitor Logs mirroring into Microsoft Fabric is in public preview, making Log Analytics workspace telemetry available in OneLake as Delta Parquet with near real-time availability and without duplicating the source data. The capability can simplify analytics over operational telemetry while connecting Azure monitoring data to Fabric-based data engineering and reporting workflows.
- Azure Firewall Adds HTTP Header Insertion. Azure Firewall generally supports adding or overwriting HTTP and HTTPS headers directly through firewall application rules. Microsoft highlights Entra tenant restrictions, Azure Virtual Desktop, SaaS access control, and enterprise egress filtering as scenarios, potentially reducing dependence on separate proxy infrastructure for these policy-enforcement patterns.
- Azure Chaos Studio Workspaces Enter Public Preview. Chaos Studio Workspaces provide a scenario-based way to simulate outages, failovers, network disruptions, and infrastructure failures before a production incident occurs. Organizations can use the capability to validate resilience assumptions, response processes, and application behavior under realistic failure conditions.
- AKS Adds GA Gateway API Application Routing. Azure Kubernetes Service now generally supports application routing with Gateway API, helping teams modernize ingress and Layer 7 traffic management around newer Kubernetes standards. This gives production AKS environments a more standardized path for routing application traffic.
- AKS Adds Encryption in Transit for Azure Files NFS. AKS also generally supports encryption in transit for Azure Files NFS volumes through the Azure File CSI driver. The feature protects data moving between container workloads and file shares without requiring application changes, strengthening data-in-transit protection for supported Kubernetes storage patterns.
Why It Matters: Azure’s AI story is increasingly about governance and production operations rather than model access alone. Security teams should pay particular attention to AI telemetry, cross-platform AI gateways, and agent governance because these layers can expose sensitive prompts, responses, identities, and actions.
Agent 365
Agent 365: Cross-Tenant Governance and Security for AI Agents
Agent 365 continues to mature as an administrative and security plane for enterprise agents. Microsoft is expanding cross-tenant management, analytics, platform integrations, and Defender-backed controls as organizations deploy more agents across Microsoft and third-party ecosystems.
- Multi-Tenant Agent Management Enters Public Preview. Administrators can view and manage agents across customer or subsidiary tenants from a single Microsoft 365 admin center experience. This is particularly relevant to managed service, holding-company, and multi-tenant operating models that need centralized agent governance.
- Agent 365 Licensing Activates Defender Protection for Agents. Agent 365 licenses now enable Microsoft Defender capabilities for AI agents, including discovery, security posture, threat detection, and real-time protection. Organizations evaluating licenses should therefore consider the included security controls as part of both agent-governance and security architecture decisions.
- Agent 365 Agents Become Connected Agents in Copilot. Agents published to Agent 365 are targeted for general availability in August as connected agents inside Copilot Chat and declarative agents, provided they support the Agent2Agent protocol. Teams can publish a specialist agent once and reuse it across multiple custom experiences rather than rebuilding the integration for each surface.
- Agent 365 Dashboard Centralizes Adoption Analytics. The Agent 365 Dashboard in Insights rolled out in July and unifies adoption and engagement information so leaders can track usage by group, identify top agents, and compare trends. Historical reporting for Copilot Studio agents is available behind a toggle in the same experience.
- Manager-Level Agent Analytics Arrive in Late August. A manager-oriented version of the Agent 365 dashboard is scheduled to roll out in late August, giving team leaders visibility into adoption within their own organizational scope. This distributes usage insight beyond tenant-wide administrators while preserving scoped reporting.
- Agent Data Can Be Exported for Analysis. Managers and analysts can now export agent data directly from the Agent 365 dashboard. The export gives organizations greater flexibility for deeper reporting, adoption analysis, or integration into broader BI processes.
- Agent Portal and Security Center Views Continue to Expand. Microsoft is continuing to separate tenant agents from local agents in the Agent 365 portal for clearer classification. The AI Agent dashboard in Microsoft Security Center is also expanding to consolidate agent risk scoring, blast radius, and recommended actions tied to security best practices.
- Connected Platforms Expand Beyond Microsoft. The Connected Platforms list now includes Anthropic Claude, Databricks Genie, and Google Vertex AI. This makes Agent 365 governance increasingly relevant in environments where enterprise agent adoption spans multiple AI ecosystems.
- Frontier Shadow AI Discovery Expands. Frontier Shadow AI now includes ChatGPT Desktop, Claude Desktop, OpenCode, and Poe Desktop. Security teams gain broader visibility into desktop AI usage that may otherwise operate outside formally governed enterprise AI channels.
What to Consider: Agent inventories are becoming a security requirement rather than simply an adoption metric. Establish ownership, approved platforms, access controls, and response procedures before agent counts and connected platforms outpace existing governance processes.
Copilot
Copilot: New Models, Broader Automation, and Stronger Governance
Microsoft 365 Copilot is expanding across models, authoring surfaces, automation, grounding, analytics, and administration. The operational theme is clear: as Copilot gains access to more content and can take more actions, governance over billing, grounding data, retention, credentials, and agent availability becomes more important.
Models and Platform
- GPT-5.6 and New Claude Models Expand Copilot Choice. OpenAI GPT-5.6 brings stronger reasoning for multi-step work, while Anthropic Claude Sonnet 5 is tuned for agentic tasks across Word, PowerPoint, and Cowork. Claude Opus 5 followed later in July for heavier reasoning workloads, while Claude Fable 5 is available as an opt-in model for Copilot Cowork Frontier users with administrative controls and separate data-retention terms that organizations should review before enablement.
- Copilot Cowork Moves Toward Usage-Based Billing. Copilot Cowork and new agent experiences are progressing with usage-based billing, making funding models, billing configuration, and governance review important for organizations enabling Frontier features. For early guidance on pay-as-you-go ownership decisions, see eGroup’s AI Ownership and Funding Models for SMBs.
- One Copilot Will Unify Microsoft AI Experiences. Microsoft is merging Copilot Chat, GitHub Copilot, Cowork, and Autopilots into a single AI experience internally referred to as One Copilot, targeted for launch later in 2026. The experience is intended to unite consumer and commercial Copilot while allowing users to switch between personal and enterprise modes, increasing the importance of clear tenant context and organizational data boundaries.
User Experience and Surfaces
- Copilot in Word Adds Review and Publishing Workflows. Copilot in Word can edit with Track Changes enabled and work with comments, tables of contents, headers, footers, and page numbers. The changes make Copilot more useful for controlled document revision because human reviewers retain visibility into proposed edits and can approve them through familiar Word workflows.
- Copilot Notebooks Add New Reference Formats. Copilot Notebooks now accept Markdown, TXT, and RTF files as references. The additional formats make it easier to ground Copilot in software documentation, transcripts, plain-text source material, and rich-text notes.
- PowerPoint Copilot Can Manage Comments. Copilot can now write, reply to, and resolve comments inside PowerPoint decks. This extends Copilot from content generation into presentation review and collaboration workflows.
- Office Agents Can Be Invoked from Copilot Chat. Users can @mention Word, Excel, and PowerPoint agents directly in a Copilot Chat prompt. This allows documents, spreadsheets, and presentations to be created without leaving the Copilot application.
- Copilot Notebooks Add Artifact Suggestions and OneNote Sync. Copilot Notebooks will suggest relevant Word, Excel, and PowerPoint artifacts based on notebook content and Microsoft 365 context and will also synchronize with OneNote. The change gives Copilot more contextual material to work from while increasing the importance of existing content permissions.
- OneNote Copilot Notebooks Add Multimodal Capture. On Windows, OneNote Copilot Notebooks are adding the ability to combine audio, images, and notes so Copilot can generate summaries, decisions, and action items. Organizations should account for the broader mix of potentially sensitive source material now being used for AI-generated output.
- Microsoft 365 Copilot Mobile Adds Voice Notes. The mobile application is adding voice-note capture with AI-generated transcripts and summaries. Recordings are stored in OneDrive and remain subject to existing Microsoft 365 governance policies, so retention, data protection, and lifecycle rules continue to apply to the captured audio.
- Copilot Pages Move to OneDrive for Business. New Copilot Pages will be stored in OneDrive for Business, bringing them under existing OneDrive governance, compliance, data-protection, retention, and lifecycle policies. This change gives administrators a more familiar compliance boundary for content created through Copilot Pages.
- PowerPoint Copilot Supports Personal Custom Skills. PowerPoint Copilot on Mac, web, and desktop is adding support for personal custom skills stored in OneDrive. This gives users a managed location for user-defined skills while making OneDrive permissions and governance relevant to how those extensions are stored and accessed.
- Copilot App Supports Organization-Branded Footers. The Microsoft 365 Copilot app can display an organization-branded footer. Administrators can use the visual treatment to reinforce that users are operating in a trusted enterprise tenant context.
Automation and Task Execution
- Teams Meeting Recaps Get a Dedicated Copilot App. A new Meeting Recaps app for Teams gathers AI-generated recaps in one pinnable location with filters and 30 days of history. Users can also generate an audio recap for more flexible meeting catch-up.
- Cowork Adds Local Browser Automation and Event Triggers. Cowork can automate tasks in Microsoft Edge across SaaS applications and internal portals while the user is signed in. It also supports event-triggered tasks that monitor mail and Teams for specific senders, keywords, or mentions and prepare a response before the user explicitly asks.
- Copilot Mobile Adds Proactive Notifications. The Copilot mobile app can send push notifications such as “Your Day at a Glance” and “Items waiting for you.” Opening a notification takes the user directly into the corresponding Copilot response, making Copilot a more proactive work surface.
- Planner Moves into Outlook and Copilot. Planner is becoming available directly in Outlook and Microsoft 365 Copilot so users can work with personal and shared tasks alongside email, calendar, and AI workflows. The integration reduces context switching while making task data available closer to daily productivity surfaces.
- Surveys Agent Is Transitioning into Forms. The Surveys agent is retiring and moving into a unified Copilot-powered experience in Microsoft Forms. Organizations with documentation or training built around the standalone Surveys agent should update their guidance as the experience consolidates.
- Scheduled Prompts Move Under Connected Experiences Policy. Scheduled Prompts in Microsoft 365 Copilot are moving under Microsoft 365 Connected Experiences policy controls. The end-user functionality remains, but administrators will govern availability through a different policy surface.
Data Access and Grounding
- More Copilot Connectors Reach General Availability. A new wave of connectors covers financial services, professional services, manufacturing, healthcare, and retail sources, including FactSet, Morningstar, PitchBook, and CB Insights. Users can scope a prompt to a single connector for more targeted answers, while organizations should continue validating access and data-governance boundaries for connected sources.
- Excel Copilot Can Ground in Governed Power BI Data. Users can attach a Power BI report to Copilot in Excel and ask for trend analysis or summaries using the governed BI data as context. Power BI row-level security continues to apply, preserving data-access restrictions while extending the data into an AI-assisted analysis workflow.
- Edge for Business Expands Copilot Chat Grounding. Microsoft 365 Copilot Chat in Edge for Business can summarize and ground responses across browser tabs, Microsoft 365 documents, and YouTube videos while respecting Microsoft 365 data-protection policies. This broadens browser-context reasoning without removing enterprise policy enforcement.
- Restricted SharePoint Content Is Removed from Copilot Discovery. SharePoint Restricted Content Discovery is being enhanced so content from restricted sites does not appear in Copilot or Microsoft 365 search. This reduces the risk of sensitive site content being surfaced through AI or search experiences merely because it is discoverable elsewhere in the tenant.
- Teams AI Meeting Archives Become Tenant-Owned Data. AI meeting archive files will capture meeting insights used by Copilot and Facilitator and will be stored in tenant-owned SharePoint. Access is limited to meeting participants, giving organizations a defined content location and permission model for the meeting-derived AI data.
Governance and Administration
- Admins Can Exclude Up to 1,000 Domains from Web Grounding. Domain exclusion allows administrators to prevent up to 1,000 websites from influencing Copilot answers. This gives organizations more control over external grounding sources when accuracy, trust, or policy requirements make certain domains inappropriate.
- Purview DLP Can Exclude External Emails from Copilot. Purview DLP can prevent externally received email from being used in Copilot responses. This creates another control point for reducing the chance that potentially untrusted external content influences AI summaries, citations, or reasoning.
- Connector Management Moves into Microsoft 365 Admin Center. Copilot connector management is being unified under Microsoft 365 admin center > Copilot > Connectors. The administrative surface changes, but existing security, compliance, and connector controls remain in place.
- App and Agent Availability Management Is Being Unified. Microsoft is consolidating availability management across Teams, Outlook, and the Microsoft 365 app. Administrators will be able to manage applications and agents more consistently across Microsoft 365 user surfaces.
- Copilot Studio Can Block Maker-Provided Credentials. A new Copilot Studio administrative control can prevent makers from supplying credentials for agent authentication. This helps organizations require end-user credentials where appropriate, reducing the risk of agents operating through shared or maker-owned identities.
Analytics and Optimization
- Copilot Dashboard Adds De-Identified Data Export. Copilot Analytics is adding de-identified export from the Copilot Dashboard for users who have full company-level access. The feature gives organizations more flexibility to analyze adoption and licensing trends outside the native dashboard.
Personalization
- Brand Kits, Reference Decks, and User Skills Expand Personalization. New brand kit and theme-design skills can format PowerPoint decks and workbooks around an organization’s visual identity, and Copilot can create a new deck styled after an existing reference presentation. Copilot can also use custom user skills stored in OneDrive, making governed skill storage and enterprise branding increasingly integrated into content-generation workflows.
What to Consider: Copilot governance should now cover far more than licensing. Review model-specific retention terms, PAYG controls, external grounding, OneDrive retention, connector permissions, agent credentials, and meeting-derived data as part of one integrated AI governance program.
Copilot Studio
Copilot Studio: More Autonomous Agent Building
Microsoft has significantly reworked Copilot Studio around agent orchestration and reusable skills. The platform is moving away from heavily hand-wired conversational logic toward agents that select tools and other agents dynamically.
- Copilot Studio Gets a Ground-Up Rebuild. Microsoft has rebuilt Copilot Studio around an orchestrator that can select its own tools and agents instead of relying on hand-wired topics, while reducing the maker setup experience from nine tabs to four. The GitHub Copilot harness is used for building autonomous agents and workflows, with usage billed through Copilot Credits and no change to existing agents.
- Workflow Designer Reaches General Availability. The new Workflow Designer became generally available on August 3. Teams can create agentic automations that reason over emails, documents, and requests and determine the next appropriate action.
- Run-Only Agent Sharing Enters Public Preview. Run-only agent sharing entered public preview in August, allowing colleagues to use an agent without editing it or seeing how it was built. The model can help separate consumption rights from maker rights when organizations need wider agent access without broader design permissions.
- Reusable Skills and Microsoft IQ Expand Agent Context. Makers can create instructions once in a Markdown file, reuse the skill across multiple agents, and export it for sharing. Microsoft IQ can connect agents to emails, calendars, files, and Teams messages, giving them access to rich Microsoft 365 context subject to the underlying access model.
Why It Matters: More autonomous agents can accelerate automation, but they also increase the importance of identity, tool permissions, Copilot Credit governance, and separation between maker and user access.
Defender
Defender: AI Agent Protection and Security Platform Changes
Microsoft Defender is expanding protection into AI agents while also moving data-protection responsibilities toward Purview and changing several existing detection and investigation behaviors. Security teams should review both the new AI protections and the operational impact of retiring or changing existing signals.
- Defender Previews Discovery and Runtime Protection for Local AI Agents. Microsoft announced preview Defender capabilities that discover local AI agents and Model Context Protocol servers on managed Windows and macOS endpoints and provide runtime protection against malicious agent activity. This extends endpoint security visibility into emerging agent processes that may otherwise execute actions with significant user or system privileges.
- Prompt-Injection Email Protection Enters Preview. Microsoft is previewing email protection designed to identify and isolate messages containing prompt-injection instructions before delivery. The control targets the emerging risk of malicious email content attempting to manipulate AI assistants or agents that later process the message.
- Defender for Cloud Expands AWS RDS Protection. Threat protection for open-source relational databases on AWS RDS is generally available in Defender for Cloud. Capabilities include anomalous-access detection, brute-force detection, and sensitive data discovery, expanding Defender coverage across multi-cloud database workloads.
- Defender for Office 365 Improves Promotional Mail Handling. Defender for Office 365 can tag promotional emails and optionally route them to a Promotions folder while learning from user behavior. This can improve inbox classification without treating promotional content as equivalent to malicious mail.
- MDO Notification Templates Become Language-Aware. Microsoft Defender for Office 365 is localizing the default Mark and Notify email template based on each user’s preferred Outlook language. The change makes automated security communications easier for multilingual user populations to understand.
- AIR Investigations Add Manual Refresh and Data Minimization. Automated Investigation and Response investigations are adding a manual refresh control and simplifying investigation names by removing email subjects and user principal names. Microsoft positions the changes as improvements to performance and data minimization, reducing sensitive identifying information displayed in investigation names.
- Endpoint Advanced Hunting Loses SMB Signature Inspection Events. Microsoft Defender for Endpoint is removing SMB signature inspection events from Advanced Hunting. Queries that depend on these events must use alternative filters, such as SMB traffic over port 445, to preserve the intended hunting or detection logic.
- Defender for Cloud Apps File Policies Are Retiring. File-policy data loss prevention capabilities in Defender for Cloud Apps are moving to Microsoft Purview. Organizations should migrate relevant data-protection controls into Purview rather than relying on the retiring Defender for Cloud Apps file-policy experience.
Quick Take: Security operations teams should test existing hunting queries and DLP workflows now while separately evaluating Defender’s emerging AI-agent detection capabilities. AI security is being added without freezing the rest of the platform, so both migration and new-control adoption need attention.
Edge for Business
Edge for Business: Faster Releases and Stronger Enterprise Controls
Edge for Business is accelerating its update cadence while adding passkey and security-management capabilities. Organizations with strict application validation requirements should revisit browser servicing strategy before the faster cycle becomes operationally disruptive.
- Edge Moves to a Two-Week Release Cycle. Microsoft Edge for Business is moving to a faster two-week release cadence. Extended Stable remains available for organizations that need additional application testing and validation time.
- Passkey Sync and Security Controls Expand. Edge is adding enterprise passkey synchronization, improved security-update alerts, and stronger browser controls for macOS. These changes extend identity and browser-management capabilities across enterprise endpoints.
- Unload Event Handlers Stop Running by Default in September. Beginning in September 2026, Microsoft Edge will stop running unload event handlers by default. Sites that still depend on unload behavior should migrate to modern page-lifecycle events or explicitly permit unload temporarily while remediation is completed.
What to Consider: Application owners should identify business applications that still depend on legacy unload behavior before September, while endpoint teams decide whether the new two-week Edge channel aligns with their testing capacity.
Entra ID
Entra ID: Passkey Transition and Authentication Modernization
Microsoft is making several significant identity changes across synchronization, MFA, Conditional Access, Authenticator, password reset, and company branding. Several deadlines fall between September 2026 and May 2027, so identity teams should treat this as a coordinated roadmap rather than isolated feature updates.
- Selected Customers Begin Moving from Connect Sync to Cloud Sync. Microsoft began notifying selected customers in July, through the Microsoft 365 Message Center, about phased transitions from Microsoft Entra Connect Sync to Entra Cloud Sync. Early waves focus on customers whose configurations are already fully supported by Cloud Sync, while large directories and environments with advanced synchronization requirements are not expected to be among the earliest migrations.
- Passkey Registration Campaign Begins September 1. Starting September 1, Microsoft will begin enabling passkeys for users currently enabled for SMS or voice authentication and prompt them to register a passkey during MFA. Organizations should prepare user communications and authentication-method policies before registration prompts begin.
- Microsoft-Provided SMS and Voice Delivery Ends February 1, 2027. Microsoft plans to stop providing the underlying SMS and voice delivery service on February 1, 2027. Organizations that still require SMS or voice authentication will need to contract with a supported telecommunications provider through the Microsoft Security Store.
- SMS and Voice Provider Details Arrive in September and October. Provider information and pricing are expected on September 18, with configuration becoming available October 30. The currently announced schedule applies to the public cloud, and Microsoft will announce sovereign-cloud timelines separately.
- Authenticator Adds Encrypted Backup and Compromised-Device Protection. The August iOS Authenticator experience adds encrypted iCloud backup and restore for account names and improves passkey restoration. New jailbreak and root detection also blocks Entra credentials on compromised devices by default, strengthening credential protection on mobile endpoints.
- Conditional Access Expands for AI Agents. Microsoft is expanding Conditional Access so organizations can secure AI agents that have accounts, including policy enforcement based on agent risk and device-compliance requirements. This allows organizations to require agents to operate from appropriately managed endpoints rather than treating agent identities as exempt from normal access governance.
- Custom Controls Retire in May 2027. Microsoft is retiring Custom Controls in Conditional Access by May 2027 and replacing them with External MFA for standardized third-party MFA integration. Organizations using custom integrations should plan migration and testing before the retirement date.
- Custom CSS Positioning in Company Branding Retires. Microsoft will retire custom CSS positioning properties in company branding beginning in October 2026. The change is intended to improve security and phishing resistance and may require organizations with heavily customized sign-in pages to update their branding.
- SSPR Will Require Explicitly Registered Authentication Methods. Beginning November 9, 2026, self-service password reset will require explicitly registered authentication methods, with a registration campaign beginning October 5. Identity teams should verify registration completeness before enforcement to reduce user lockout and support-volume risk.
- Windows Hello and macOS Platform SSO Become Standalone MFA Factors. Starting in October 2026, Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors. This can affect Conditional Access design and authentication-strength planning for managed Windows and macOS devices.
Why It Matters: Passkeys, agent identities, sync modernization, and MFA changes are converging. Build one authentication modernization plan that covers user registration, legacy SMS and voice dependencies, third-party MFA, device-bound credentials, and emerging agent accounts.
Fabric & Power BI
Fabric & Power BI: Runtime, Governance, and Reporting Enhancements
Fabric and Power BI received updates across Spark runtimes, OneLake governance, real-time data, geospatial workloads, modeling, mobile experiences, organizational apps, and report design. The overall direction is toward stronger web-based development, governed distribution, and lower-friction analytics.
- Fabric Runtime 2.0 Enters Preview. Microsoft Fabric Runtime 2.0 is in preview on Apache Spark 4.1, Delta Lake 4.2, and Python 3.13 and includes a longer support window for large analytics and AI workloads. New Runtime Release Channels let teams test upcoming runtime changes before those versions become the default.
- Lakehouse Query Explorer Becomes Available. Lakehouse Query Explorer enables immediate querying of lakehouse data. The native execution engine also accelerates Python and Scala UDFs and complex data types without requiring code changes.
- OneLake Govern Tab Gets Action-Level Detail. The OneLake catalog Govern tab now identifies the specific items behind recommended governance actions. Data owners can move directly to resources with issues such as missing sensitivity labels, unused items, or failed refreshes rather than working from a generic recommendation.
- Real-Time Intelligence Adds Oracle CDC. An Oracle Change Data Capture connector for Eventstream is available in preview. This expands Fabric’s ability to ingest and react to changes from Oracle-backed operational systems.
- Fabric Maps Adds Tilesets. Fabric Maps Tilesets support high-performance visualization of large geospatial datasets. The capability is designed for analytics scenarios where geospatial volume makes traditional rendering less practical.
- Git Branch Switching Expands to Contributors. Users with the Contributor role can now switch Git branches without requiring an administrator. This reduces friction for development teams using source-control workflows in Fabric.
- Modern Visual Defaults Gain Theme Customization. The Power BI modern visual defaults preview adds a Customize current theme experience for report-wide colors, borders, padding, and page size. New visuals inherit the selected design settings, and themes can be exported for reuse.
- Conditional Formatting Expands to Line Charts and Legends. Conditional formatting now applies to line charts and visuals with legends. A single DAX measure can drive a segment’s color consistently across every visual using that legend.
- Org Apps with Audiences Reach GA. Power BI organizational apps with audiences are generally available, allowing one governed application to present finance content to one audience and operations content to another. Bookmarks, PowerPoint Storytelling embedding, and REST management APIs now work with org apps as well.
- Org App Audiences Reach Mobile. Audience-aware organizational apps now extend to the iOS and Android Power BI applications. Mobile users receive an experience curated for their role rather than losing audience-based navigation away from the desktop.
- More Modeling Moves to the Web. Model Options are available in the Power BI Service, and a new TMDL View gives developers a code editor for scripting model changes. Developers can also add measure descriptions inline with triple-slash comments immediately above a measure definition.
- Report Page Tab Navigation Improves. Dragging a report page tab toward an edge now continues scrolling until the desired position is reached. The update improves the editing experience for reports containing large numbers of pages.
Why It Matters: Fabric administrators should use Runtime Release Channels and governance recommendations to reduce change risk, while Power BI teams can increasingly manage development and governed distribution without relying exclusively on desktop workflows.
Exchange Online
Exchange Online: EWS and Legacy TLS Retirements Require Preparation
Exchange Online continues its transition away from legacy protocols and APIs. Cross-tenant collaboration and older POP or IMAP clients are the primary areas requiring proactive migration work.
- EWS Retirement Affects Cross-Tenant Collaboration. Exchange Web Services deprecation will affect cross-tenant Free/Busy, MailTips, and Calendar Sharing. Organizations using these capabilities must migrate to Microsoft 365 Cross-Tenant Access Policy before EWS shutdown on April 1, 2027.
- EWSAllowedAppIDs Supports Controlled Migration. Exchange Online is adding EWSAllowedAppIDs so administrators can permit specific applications while EWS retirement work is underway. The control can reduce disruption during migration, but it should be treated as a transition mechanism rather than a reason to postpone modernization.
- Cross-Tenant Message Recall Is Coming. Exchange Online will support message recall across trusted external Microsoft 365 tenants. Administrators will be able to enable and manage the capability using allow-listed tenant IDs.
- TLS 1.0 and 1.1 Retire for POP3 and IMAP4. Legacy TLS 1.0 and TLS 1.1 support for POP3 and IMAP4 connections is retiring. Clients and applications must use TLS 1.2 or later to maintain connectivity.
What to Consider: Inventory both EWS applications and legacy mail clients now. Cross-tenant calendar dependencies can be easy to miss, and application-specific EWS allowances should have explicit migration owners and expiration plans.
Intune
Intune: Better Sync Visibility and Broader Compliance Controls
Intune’s updates improve administrative visibility into Windows check-ins while expanding compliance capabilities for macOS and management support for Samsung devices. Defender XDR integration also gives security teams more centralized incident context.
- Windows Device Sync Shows Progress and Runs Both Check-Ins. The updated Windows device sync experience displays progress while triggering both the MDM check-in and the Intune Management Extension check-in. A single administrator action can therefore retrieve policy, application, and script changes while showing where synchronization is succeeding or failing.
- Custom macOS Compliance Settings Reach GA. Custom macOS compliance settings are generally available, allowing organizations to evaluate requirements that Microsoft’s built-in compliance controls do not cover. This gives security teams more flexibility to translate environment-specific macOS requirements into device-compliance policy.
- Samsung Firmware Management Expands. Microsoft introduced additional controls for managing Samsung firmware deployment. Organizations with managed Samsung fleets gain additional options for controlling device firmware as part of endpoint lifecycle management.
- Intune Alerts Gain Defender XDR Incident Correlation. Alerts can be flagged for correlation, and resulting incidents are surfaced in the Defender XDR portal. The integration can reduce fragmentation between endpoint-management signals and security-operations workflows.
Quick Take: Custom macOS compliance and Defender incident correlation are the strategic changes, while the improved Windows sync experience should make day-to-day troubleshooting materially easier for endpoint administrators.
Microsoft 365 Apps
Microsoft 365 Apps: Major E3 and E5 Packaging Changes
Microsoft completed its summer packaging changes on August 1, adding security, Intune, and AI capabilities to key Microsoft 365 plans. The changes can materially affect both feature availability and the economics of standalone security and management products.
- Microsoft 365 E3 Adds Security and Intune Capabilities. Microsoft 365 E3 now includes Microsoft Defender for Office 365 Plan 1, Intune Remote Help, Intune Advanced Analytics, and Intune Plan 2. Organizations should review existing standalone licensing and deployment plans to determine where bundled entitlements can replace separate purchases or enable capabilities that were previously unavailable.
- Microsoft 365 E5 Adds Security Copilot and Advanced Intune. Microsoft 365 E5 receives the E3 additions plus Microsoft Security Copilot, Intune Endpoint Privilege Management, Microsoft Cloud PKI, and Intune Enterprise Application Management. These additions increase the value of E5 for organizations consolidating security, privilege, certificate, and application-management tooling.
- Office 365 E3 Adds Defender for Office 365 Plan 1. Office 365 E3 now includes Defender for Office 365 Plan 1. Security teams should validate how the entitlement fits existing mail-protection licensing and deployment architecture.
- Defender Suite and Purview Suite Launch as Standalone Offers. Microsoft introduced standalone Defender Suite and Purview Suite offerings at a commercial list price of $12 per user per month. These options give organizations another packaging path for security or compliance capabilities without necessarily moving every user to a broader Microsoft 365 suite.
- Multiple Microsoft SKUs Received July Price Increases. Several Microsoft 365, EMS, Windows, and Entra SKUs received price increases on July 1. Organizations should incorporate the new rates into renewal, license-optimization, and budget planning rather than comparing future scenarios against earlier pricing.
Why It Matters: Licensing changes can create both savings and duplication. Reconcile actual entitlements against deployed products before renewing standalone tools, and include the July price increases in any Microsoft 365 cost model.
OneDrive
OneDrive: Copilot Governance and Windows Support Changes
OneDrive is becoming an increasingly important governance layer for Copilot-generated content while also tightening support expectations for Windows clients. Administrators should review retention and endpoint lifecycle together.
- Copilot Pages Are Stored in OneDrive for Business. Newly created Copilot Pages will be stored in OneDrive for Business. Existing OneDrive governance, retention, data-protection, compliance, and lifecycle controls can therefore apply to those pages rather than requiring a separate content-governance mechanism.
- Long File Path Sync Errors Become Clearer. OneDrive for Business on Windows is improving error messages for paths that exceed supported length limits. The change should help users diagnose and resolve path problems without unnecessarily stopping synchronization.
- Older Windows 10 Versions Stop Receiving OneDrive Sync Updates. The OneDrive sync application will stop receiving updates on older Windows 10 versions. Affected devices must move to a supported Windows release to continue receiving sync-client updates and associated improvements.
What to Consider: Treat unsupported Windows versions as both an endpoint and data-access concern. A stale OneDrive client can become an operational issue even when the underlying Microsoft 365 service remains fully supported.
Outlook
Outlook: Copilot Expansion and Government Availability
Outlook continues to shift meeting preparation toward Copilot while extending New Outlook into additional government environments. Mobile and classic Outlook are also receiving targeted usability and AI improvements.
- Meeting Insights Retires in Favor of Copilot Meeting Preparation. Outlook Meeting Insights is retiring and will be replaced by Microsoft 365 Copilot meeting-preparation features for appropriately licensed users. Organizations should review licensing and user guidance before relying on the replacement workflow.
- New Outlook Expands to GCC High and DoD. New Outlook for Windows is becoming available in GCC High and DoD as an opt-in experience controlled through administrative policy. Government organizations can evaluate the newer client while retaining deployment control.
- Outlook Mobile Clarifies RSVP Status. Outlook Mobile will make meeting responses easier to understand by visually highlighting the selected RSVP choice. The change is primarily a usability improvement for mobile calendar workflows.
- Classic Outlook Adds More Copilot Entry Points. Classic Outlook for Windows is adding Copilot settings, user-initiated Copilot insights, and a new Copilot entry point. These changes make AI capabilities easier to reach within established email workflows rather than requiring an immediate move to New Outlook.
Planner
Planner: Tasks Move Closer to Daily Workflows
Planner is becoming more deeply integrated into Microsoft 365 productivity surfaces. Microsoft is also expanding where Planner tabs can be used inside Teams.
- Planner Integrates with Outlook and Microsoft 365 Copilot. Users can manage personal and shared tasks closer to their email, calendar, and Copilot workflows. The integration reduces context switching and makes Planner more visible during everyday work.
- Planner Tabs Expand to More Teams Channel Types. Planner tab support is coming to both shared and private Teams channels. Teams that work outside standard channels can manage plans without moving task coordination into a separate workspace.
Why It Matters: Deeper Microsoft 365 integration may increase Planner adoption without a formal migration project. Governance and task-management standards should account for plans appearing in more channel and productivity contexts.
Power Platform
Power Platform: Modern Controls, Shared Capacity, AI Development, and Security
Power Platform’s August changes span Power Apps, Power Automate, and Power Pages. Makers gain modern controls and AI-assisted development options, while administrators get new licensing visibility and a preview security agent.
- Data Grid Modern Control Reaches GA. The data grid modern control is generally available for canvas applications, providing a fast, searchable, sortable tabular experience with rich column types based on Fluent UI. A table-to-data-grid upgrade path helps makers modernize existing applications rather than rebuild the experience from scratch.
- Modern Toggle, Checkbox, and Form Controls Improve. Modern toggle and checkbox controls now use more consistent naming, tooltips, a true read-only view mode, and additional output properties that formulas can reference. The modern form control also received data-card, binding, and reset fixes aimed at improving form reliability.
- Fluent 2 Templates and Controls Expand. New Fluent 2 application templates provide hub, feature, and list-page layouts rather than starting makers from a blank screen. A new rating control, richer card-text styling, and an expanded library of 180 icons further broaden the modern control set.
- Flow Groups Share Process Capacity Across Cloud Flows. Power Automate flow groups allow one process license, or 250,000 actions per day, to be shared across up to 25 solution-aware cloud flows. The model can make licensed capacity more efficient across flows with steady and predictable usage.
- Power Automate Plugin Comes to AI Coding Assistants. A new Power Automate plugin is available in the skills marketplace for GitHub Copilot CLI and Claude Code. Makers can create, edit, run, and debug cloud flows from the terminal using natural language, with generated definitions available for review before anything is enabled or published.
- Power Pages Security Agent Enters Public Preview. A new security agent can review site security, configure authentication, and troubleshoot sign-in problems through natural-language interaction. The agent requests administrator approval before making changes, preserving a human control point for security-impacting actions.
- Power Automate Licensing Dashboard Is Refreshed. The licensing dashboard has a consolidated layout and clearer detail on license consumption. The update is intended to help administrators understand usage and manage Power Automate cost more effectively.
- Custom Process Intelligence KPIs Reach GA. Custom KPIs are generally available in the process-intelligence experience. Organizations can define metrics that better reflect their own operational and process-analysis requirements.
- Power Apps Global Search Adds Entity Scoping and Multi-Select Filters. Entity scoping in global search and multi-select grid-column filtering are in public preview for model-driven applications. Users can narrow search results by table and multiple field values to reach relevant records more efficiently.
- Legacy Power Automate Chatbot Retires September 2. The legacy chatbot in the Power Automate portal retires on September 2. Existing flows and established support channels are not affected by the retirement.
What to Consider: AI-assisted development is moving directly into both maker and command-line workflows. Organizations should combine maker enablement with solution lifecycle controls, licensing monitoring, review-before-publish practices, and clear boundaries for AI-driven administrative changes.
Purview
Purview: Copilot DLP and Insider Risk Workflow Changes
Purview is becoming a more central control plane for protecting data used by Copilot while also consolidating Insider Risk Management alert handling. Both updates can affect existing analyst procedures and compliance operations.
- DLP Can Block External Email from Copilot Grounding. In preview, Purview DLP can prevent Microsoft 365 Copilot and Copilot Chat from using externally received email as grounding material. The control compares the sender domain with the tenant’s accepted domains and excludes matching external messages from Copilot summarization, citation, and reasoning while leaving the original email accessible to the user.
- External Email Grounding Control Uses Metadata, Not Message Content. The DLP rule evaluates sender metadata rather than inspecting the email body. This distinction matters for compliance design because the policy governs whether an externally sourced message can participate in Copilot reasoning without acting as a content-inspection or quarantine mechanism.
- Insider Risk Moves to a Unified Alert Experience. Purview Insider Risk Management is combining classic alerts and Triage Agent alerts into one experience. After August 31, only the unified alert experience will be supported.
- Alert Spotlight Is Replaced by Needs Attention. Alert Spotlight is being removed and replaced with the Needs Attention filter for alerts prioritized by the agent. Organizations should update analyst procedures, screenshots, training material, escalation guides, and operational metrics that currently depend on Alert Spotlight or separate classic and Triage Agent dashboards.
Why It Matters: These are operational governance changes, not cosmetic UI updates. DLP affects what data Copilot can reason over, while Insider Risk changes may invalidate established SOC or compliance procedures if documentation and measurements are not updated.
SharePoint Online
SharePoint Online: Oversharing Visibility and Tighter Content Governance
SharePoint is adding more visibility into broad permissions while tightening how sensitive content appears in search and Copilot. External authentication and legacy customization are also moving toward newer Microsoft standards.
- New Report Identifies Broadly Shared Items. SharePoint is adding an item-level report showing permissions granted through Everyone and Everyone except external users groups. Administrators can use the report to identify content that may be overshared rather than relying only on site-level permission analysis.
- AI-Assisted Charts Web Part Is Coming. Page authors with the appropriate license will be able to create interactive charts using natural-language prompts through a new AI-assisted Charts web part. Organizations should account for both licensing and the underlying data-access permissions when enabling AI-generated visualization experiences.
- Restricted Content Discovery Becomes More Restrictive. Content from sites governed by SharePoint Restricted Content Discovery will no longer surface through Copilot or Microsoft 365 search. The enhancement gives organizations stronger control over sensitive content discovery beyond direct site access.
- Classic Publishing Custom Scripting Is Tightened. SharePoint changes will disable custom scripting by default on classic publishing sites and block creation of new classic publishing sites. Organizations with legacy publishing customizations should identify dependencies and plan modernization.
- SharePoint One-Time Passcode Authentication Is Retiring. SharePoint One-Time Passcode authentication for external sharing is being retired in favor of Microsoft Entra B2B. External-collaboration processes should be reviewed to ensure guest access and identity lifecycle controls are compatible with the Entra B2B model.
What to Consider: SharePoint remains central to both traditional collaboration and AI grounding. Prioritize oversharing remediation and Restricted Content Discovery because Copilot increases the practical impact of content that is technically accessible but was previously difficult for users to find.
Sentinel
Sentinel: Automation Schema Changes and More Azure Portal Migration Time
Microsoft has extended the Sentinel Azure portal transition timeline, but new functionality continues to favor the Defender portal. A separate account-entity mapping change requires immediate attention because it can silently disrupt downstream automations.
- Sentinel AccountName Mapping Has Changed. Microsoft standardized the Sentinel account entity mapping so that
AccountNamecontains only the UPN prefix. Complete identity information is now represented through fields such asUserPrincipalNameandUPNSuffix. - Existing Automations May Silently Stop Matching. Logic Apps, automation rules, and integrations that compare
AccountNamewith a complete address such asuser@domain.commay no longer match correctly. Microsoft recommends updating conditions to use the separate UPN fields or less brittle matching logic, and organizations should review the automation layer rather than only validating analytics rules because a detection can still fire while its downstream response silently fails. - Azure Portal Support Extends to March 31, 2027. Microsoft has extended support for Sentinel in the Azure portal through March 31, 2027, providing more migration time than the previously announced July 2026 timeline. The Defender portal remains Microsoft’s strategic destination, so customers should use the extension for structured migration testing rather than delaying the move.
- Defender Portal Migration Testing Should Cover the Full Workflow. Organizations should use the additional time to validate RBAC, connectors, playbooks, workbooks, analyst workflows, and third-party integrations in the Defender portal. Testing only basic alert visibility can miss operational dependencies that affect incident response.
- New Sentinel Capabilities Are Increasingly Defender-Portal-First. Preview capabilities include pre-ingestion filtering and splitting, Fabric-based data federation, custom security graphs, row-level data scoping, and a customer and partner cost-estimation tool. The feature direction reinforces the need to treat Defender portal migration as an architectural transition rather than a future UI preference.
Why It Matters: The AccountName change can create a dangerous false sense of security because analytics may continue working while automated response fails. Validate identity-dependent Logic Apps and rules now, then use the extended Azure portal window to complete a deliberate Defender portal migration.
Teams
Teams Security — Deepfake Reporting + External Bot Detection
- Report a Concern Targets Deepfake and Impersonation Risk. Teams is rolling out a Report a concern button that allows participants to flag suspected deepfake or impersonation activity during a meeting for immediate IT intervention. Microsoft is also adding detection of external meeting bots with organizer controls over what those bots can do, forming part of a broader defense against AI-driven meeting fraud.
Teams Chat & Channels — Smarter Organization + Stronger External Controls
- Muted Chats and Meeting Chats Get Dedicated Sections. Teams is adding two system sections called Muted chats and Meeting chats. Conversations are automatically grouped into dedicated collapsible areas that users can turn on or off.
- Teams Live Chat Retires by Mid-October 2026. Microsoft Teams live chat is retiring by mid-October 2026. Organizations using live-chat widgets should identify and remove or replace those integrations before retirement.
- Federated Group Chats Gain Stronger External Controls. Teams is adding stricter external-access controls for federated group chats, including PowerShell controls that can enforce approved external users and mutual federation requirements. Administrators can more narrowly govern who participates in cross-tenant group conversations.
- Shifts Adds Smarter Open-Shift Assignment. Managers will be able to assign open shifts using employee availability, time off, and scheduling rules before publishing a schedule. The feature brings more decision support into frontline scheduling workflows.
- Certified Third-Party App Rules Come to Teams Admin Center. Teams admin center is adding rule-based controls for Microsoft 365-certified third-party Teams applications. No tenant-wide behavior changes unless an administrator explicitly enables the setting.
Teams Meetings — Refreshed Controls + AI-Powered Meeting Experiences
- In-Meeting Controls Are Being Refreshed. Teams is simplifying meeting controls, separating the Leave button, allowing greater control customization, and improving the sharing panel with smarter confirmation steps. The update is intended to reduce meeting friction while lowering the risk of accidental actions.
- Speaker-Focused Event Layout Rolls Out Through August and September. A new speaker-focused layout for Teams events prioritizes presenter video alongside shared content. The experience is particularly relevant to organizations that regularly run presentation-heavy events.
- AI Meeting Archive Files Store Insights in SharePoint. Teams AI meeting archives will capture meeting insights used by Copilot and Facilitator and store those files in tenant-owned SharePoint. Access is limited to meeting participants, providing a defined tenant-controlled repository for the AI-derived meeting data.
- Private Presenter Chat Comes to Structured Events. Organizers, co-organizers, and presenters will gain a private chat for structured meetings, webinars, and town halls. The feature creates a unified back-channel for event production and coordination.
- Meeting Activity Can Be Reported to Security Teams. Teams users will be able to report suspicious or malicious meeting activity. Reports will be available to security teams through Microsoft Defender and Teams admin center, linking participant reporting with administrative investigation.
- Live Captions Get a New Right-Side Panel. Teams live captions are adding a right-side panel, consolidated settings, automatic enablement options, synchronized translation settings, and easier feedback submission. The changes centralize accessibility and translation controls during meetings.
- Breakout Rooms Scale to 1,000 Attendees. Breakout rooms now support meetings with up to 1,000 attendees and up to 200 breakout rooms. Large event organizers gain significantly more room capacity for structured sessions.
- Town Halls Support Custom Managed Backgrounds. Teams Premium town hall organizers and presenters can upload custom background images for managed attendee layouts. Organizations can use the capability to create more consistent branded event experiences.
Teams Rooms — Modernized Android Experience + Better Room Management
- Rooms on Android Gets a Modernized Gallery. Starting in mid-August, Teams Rooms on Android receives a Gallery experience aligned with Windows, including consistent tile ratios, video prioritization, stable layouts, and new administrative display controls. Mixed-platform room estates should therefore see more consistent meeting presentation.
- Offline Android Rooms Require Manual Portal Migration. Offline or signed-out Teams Android devices must be manually migrated to the Teams Rooms Pro Management portal. Devices that remain outside the migration can create management gaps, so administrators should inventory rooms that are offline or not regularly connected.
- Rooms Pro Adds Building-Level BYOD Insights. Teams Rooms Pro Management is adding building-level insights to Recommended Actions. Administrators can identify high-use buildings and locations that still contain BYOD rooms and prioritize modernization accordingly.
Teams Phone — Critical Android Update + Easier Call Flow Troubleshooting
- Teams Android Phones Must Receive Teams Admin Agent AA 830 Before September 1. Teams Android Phones must be updated to Teams Admin Agent version
1.0.0.202606082157.product, also referred to as AA 830. Phones that are online should update automatically, but devices stored unplugged or offline will not, so organizations should take stored phones out, connect them, and complete the update before September 1 to avoid devices becoming unusable when brought back into service. - Call Flow Visualizer Simplifies Voice Troubleshooting. Teams Admin Center now includes a Call Flow Visualizer that provides an interactive tree-style view of Auto Attendant and call-queue routing. Voice administrators can use it to troubleshoot call paths without manually reconstructing routing logic.
- Group Calls Add Suspicious-Activity Reporting. Teams group calls are gaining a user-facing option for reporting suspected malicious or suspicious activity. Reports can then be reviewed by administrators and security teams.
Teams Premium — Enhanced Event Production + Live Copilot Analysis
- Teams Premium Expands Event Production Features. Teams Premium continues to add production capabilities including town hall custom backgrounds, backup RTMP streams, SRT support, and structured-meeting controls. These capabilities give organizations more resilient and professional options for large managed events.
- Copilot Can Analyze Live Shared Content. Rolling out in August, Copilot can analyze screen-shared documents, slides, and spreadsheets during a meeting in real time. Users can therefore ask questions about presented material while the meeting is still happening instead of waiting for a final transcript, increasing both the value of Copilot and the need to consider the sensitivity of content being shared live.
Windows
Windows: August Quality Update and LTSC Lifecycle Deadline
Windows receives a broad quality-focused update this month while Windows 10 Enterprise LTSC 2021 moves closer to end of support. Endpoint teams should plan both near-term patching and longer-term lifecycle transitions.
- KB5101684 Ships for Windows 11 24H2 and 25H2. The August 11, 2026 update, KB5101684, is a quality-focused release for Windows 11 24H2 and 25H2. It adds Windows Hello Enhanced Sign-in Security support, the ability to uninstall AI models from Copilot+ PCs, new touchpad gestures, Voice Access voice isolation, and Fluid Dictation.
- Windows Search and Reliability Improvements. The same August update includes faster Windows Search, File Explorer stability fixes, and more reliable sign-in on systems with low memory. Organizations should evaluate the update through normal deployment rings before broad production rollout.
- Windows 10 Enterprise LTSC 2021 Ends Support January 12, 2027. Windows 10 Enterprise LTSC 2021 reaches end of support on January 12, 2027. Extended Security Updates will be available for purchase beginning September 1, 2026, giving organizations a temporary path for devices that cannot complete migration before end of support.
Why It Matters: The LTSC deadline is close enough to require concrete migration or ESU decisions now. Use the August servicing cycle to identify remaining LTSC 2021 devices and assign an upgrade or exception path before 2027 budget and change windows tighten.
Windows 365
Windows 365: Cloud PCs Built for AI Agents
Windows 365 is extending the Cloud PC model beyond human users to autonomous agents. The preview gives agents managed Windows or Linux environments for applications that cannot be reached through APIs.
- Windows 365 for Agents Enters U.S. Public Preview. Windows 365 for Agents provides AI agents with pooled Windows or Linux Cloud PCs for computer-use tasks, provisioning them on demand and returning them to the pool after a task completes. Agents can automate legacy or UI-only applications that do not expose APIs while remaining governed through Microsoft Entra and Intune.
- Agent Cloud PCs Use Task-Based Hourly Billing. Windows 365 for Agents is priced at $0.40 per hour, billed per task during the public preview described in the source notes. Organizations should factor task duration, concurrency, access rights, and the sensitivity of applications an agent can operate into both governance and cost models.
What to Consider: Giving an AI agent a managed Cloud PC can unlock applications that were previously difficult to automate, but it also gives the agent a powerful interactive environment. Treat agent identity, Intune policy, application access, credential exposure, and cost monitoring as first-class deployment requirements.