What’s New in the Hybrid Data Center & Microsoft | September 2026

Hybrid Data Center Team

eGroup

Security, identity resilience, AI governance, and infrastructure flexibility are driving this month’s most consequential IT changes. Organizations should pay particular attention to upcoming VMware, Entra ID, Defender for Cloud Apps, Intune, Windows, and licensing or retirement deadlines while evaluating a rapidly expanding set of AI, cyber recovery, and multicloud capabilities.


What’s the Buzz at eGroup This Month?

Cloud, AI, & Security: A Unified Strategy Virtual Workshop

Wednesday, October 21st | 1PM – 5PM EST
Our half-day virtual workshop brings together Microsoft experts to discuss the cloud, security, AI, and licensing decisions shaping business IT, with guidance on adopting Copilot and agentic AI while controlling costs and reducing risk.


What’s New in the Hybrid Data Center?

Rubrik

Keep Recovery Outside The Blast Radius
Rubrik is reinforcing a fundamental cyber resilience principle: backup and recovery infrastructure cannot provide a reliable last line of defense if attackers can compromise it alongside production systems.

View full Rubrik update
  • Separate recovery infrastructure from the production blast radius. Rubrik is challenging organizations to evaluate whether their recovery platform can be compromised through the same identities, infrastructure, or attack paths as production. An isolated, immutable, zero-trust recovery architecture helps preserve recovery capabilities when ransomware or another destructive attack reaches the primary environment.
  • Validate clean recovery points before restoration. Rubrik also emphasizes the importance of identifying known-clean recovery points instead of assuming that the newest available backup is safe to restore. This can reduce the risk of reintroducing compromised data or attacker persistence during recovery and makes clean-point validation a critical part of ransomware readiness. Read Rubrik’s guidance on recovery architecture.

Why It Matters: Cyber recovery planning should validate not only whether backups exist, but whether backup infrastructure, credentials, recovery metadata, and clean restore points remain usable after a production compromise.


Cohesity

Identity Resilience Moves Into Cyber Recovery
Cohesity is emphasizing Active Directory recovery as a core component of enterprise cyber resilience while also demonstrating how AI interfaces could reshape recovery operations.

View full Cohesity update
  • Active Directory recovery requires more than restoring a backup. Cohesity’s two-part identity resilience series explains how attackers target Active Directory to escalate privileges, establish persistence, move laterally, and disrupt broader environments. The recovery challenge is therefore identifying malicious or compromised directory changes and restoring AD to a known-clean state rather than simply selecting the most recent backup. Read Part 1 on Active Directory attack risk and Part 2 on Cohesity Identity Resilience.
  • Cohesity Maestro is extending cyber resilience into AI workflows. Cohesity demonstrated how Maestro will integrate with Claude through the open Model Context Protocol, or MCP, allowing operations teams to access cyber resilience intelligence and recovery workflows from AI tools they already use. The model points toward more conversational recovery operations while making governance, identity, and authorization controls increasingly important around AI-initiated actions. Read Cohesity’s demonstration of Maestro and Claude.

Quick Take: Identity services should be treated as a recoverable workload with their own compromise detection, clean-state validation, and restoration procedures.


Nutanix

More Choice Across Kubernetes, AVD, Storage, & Cloud
Nutanix continues expanding workload placement options across virtualized infrastructure, bare metal, public cloud, desktop virtualization, and external enterprise storage.

View full Nutanix update
  • NKP Metal brings Kubernetes management to physical servers. The upcoming Nutanix Kubernetes Platform capability is designed to let organizations run and manage Kubernetes across both Nutanix AHV virtual machines and physical bare-metal servers through a unified operational framework. This can give platform teams more freedom to place container workloads according to performance, hardware, or application requirements without creating separate management models. Read the NKP Metal announcement.
  • Azure Virtual Desktop Hybrid support is generally available on Nutanix AHV. Organizations can now deliver the Azure Virtual Desktop experience from on-premises Nutanix AHV infrastructure. This expands deployment options for customers that need Azure-aligned desktop services while keeping desktop compute or associated workloads in their own data centers. Read the AVD Hybrid announcement.
  • Nutanix is positioning infrastructure flexibility as an answer to hardware constraints. The company highlights NCM, NDB, and NUS for infrastructure optimization, NCI for hardware flexibility, and NC2 and NKP for on-demand capacity and workload mobility. The broader goal is to keep modernization initiatives moving without forcing organizations to absorb higher hardware costs or wait for a specific infrastructure platform. Read Nutanix’s modernization playbook.
  • Workload placement remains central to the Nutanix hybrid-cloud strategy. In its comparison of neoclouds and hyperscalers, Nutanix argues for choosing infrastructure based on workload requirements rather than defaulting to a single deployment model. That becomes increasingly relevant as organizations balance AI infrastructure economics, data locality, performance, sovereignty, and cloud operating models. Read the Nutanix perspective on neoclouds and hyperscalers.
  • NCI 7.6 supports Dell PowerStore external storage. Customers with existing PowerStore investments can adopt Nutanix AHV and the Nutanix cloud operating model without immediately replacing established storage infrastructure. This provides a potentially lower-disruption modernization path for environments where compute virtualization and storage refresh cycles do not align.

What to Consider: Nutanix customers should evaluate infrastructure choices at the workload level, especially where existing storage investments, Kubernetes requirements, AVD placement, or hardware availability influence modernization timing.


Everpure (formerly Pure Storage)

FlashStack Preserves VMware Flexibility
Everpure, formerly Pure Storage, is extending its converged infrastructure strategy with a validated VMware architecture while preserving flexibility for future platform decisions.

View full Everpure update
  • FlashStack adds a Cisco Validated Design for VMware vSphere Foundation 9.1. The new architecture combines Cisco UCS compute, Nexus and MDS networking, and Everpure FlashArray storage into a validated infrastructure stack for modern VMware workloads. This gives organizations a tested design for deploying VMware vSphere Foundation 9.1 across enterprise compute, networking, and storage components. Read the FlashStack for VVF 9.1 announcement.
  • The disaggregated architecture preserves future platform choice. FlashStack for VVF 9.1 keeps compute and storage separate, allowing customers to modernize VMware without requiring their storage strategy to be tied permanently to the same platform decision. Everpure also highlights validated FlashStack paths for Nutanix and Red Hat OpenShift, giving organizations additional options as virtualization and application-platform strategies evolve.

Quick Take: The value of the FlashStack design is not only VMware validation today, but the ability to preserve infrastructure flexibility if the organization’s virtualization or application-platform strategy changes later.


Nerdio

More Control for Windows Cloud Environments
Nerdio is focusing on endpoint risk reduction through Azure Virtual Desktop and deeper operational controls for large Windows Cloud deployments.

View full Nerdio update
  • Azure Virtual Desktop can reduce endpoint data exposure. Nerdio highlights how keeping sensitive data inside a hosted desktop environment can change the risk profile of a lost or stolen endpoint. When properly designed, the loss of the physical device becomes primarily a hardware incident rather than automatically becoming a data-loss event because protected application data can remain inside the hosted environment. Read Nerdio’s AVD security discussion.
  • Nerdio Manager for Enterprise 8.1 expands AVD and Windows 365 management. Global Pools for AVD, currently in preview, can group host pools and assign or reassign users based on Microsoft Entra group membership. The release also adds deeper Real-Time Insights for host and session troubleshooting, a Scripted Sequences Concurrency Balancer for automation control, and expanded Windows 365 management capabilities. Read about Nerdio Manager for Enterprise 8.1.

Why It Matters: Larger AVD estates increasingly require identity-aware placement, automation controls, real-time troubleshooting, and clear separation between endpoint devices and the data users access.


VMware

AVS Deadlines and Private AI Reshape the Roadmap
VMware customers face important Azure VMware Solution licensing deadlines while Broadcom positions VMware Cloud Foundation as an infrastructure layer for enterprise AI.

View full VMware update
  • Azure VMware Solution license-included PayGo SKUs retire October 31, 2026. Organizations using affected AVS consumption models should validate their licensing and migration plans now. The deadline is particularly important for environments where AVS is part of a broader data center exit, application migration, or hybrid-cloud strategy.
  • AVS license-included service retires August 30, 2027. Customers using license-included Reserved Instance SKUs must purchase portable Broadcom VMware Cloud Foundation licenses and transition to an AVS VCF BYOL SKU before that date. Organizations that do not complete the change risk service disruption beginning August 31, 2027, making contract planning, license portability, and migration sequencing immediate concerns.
  • VMware Cloud Foundation is evolving into a Private AI platform. VMware Explore 2026 introduced VMware AI Factory, which is intended to simplify the path from infrastructure to production AI by combining VCF, AI-ready hardware, accelerators, models, and automation. The strategy emphasizes greater organizational control over data placement, infrastructure, and AI economics.

What to Consider: AVS customers should treat the 2026 and 2027 licensing dates as architecture deadlines, not procurement-only events, and align those decisions with broader VCF, private AI, and platform modernization plans.


What’s New in Microsoft Cloud?

Azure

Azure: New AI Models, Multicloud Networking, and Operations Integration

Azure is expanding AI model availability while improving private multicloud connectivity, lower-cost telemetry options, and IT service management integration.

  • GPT-6 Astra is generally available through the Microsoft Foundry Limited Access Program. Availability is expanding to participating customers, creating another option for reasoning-intensive AI workloads in the Azure ecosystem. Organizations should evaluate access requirements, model governance, data handling, and cost before moving regulated or sensitive workloads to a newly available model.
  • Claude Fable 5.1 is generally available. The model includes safeguards that provide fallback behavior for certain cyber and biological capability queries. Security and AI governance teams should account for these model-level safeguards when testing agent behavior and designing workflows that depend on specialized technical responses.
  • Azure Multicloud Interconnect provides private Azure-to-AWS connectivity. The cloud-native service is intended to reduce networking complexity for applications, data, and AI workloads operating across both cloud platforms. This can simplify architectures that would otherwise require more custom networking components to maintain private intercloud traffic.
  • Azure Monitor expands Auxiliary table plan flexibility. Azure table support, table-plan switching, and sovereign-cloud support are now generally available for the Log Analytics Auxiliary plan. These capabilities give customers more options for retaining high-volume logs that do not require the full feature set and cost profile of the Analytics plan.
  • Azure Monitor issues can synchronize with ServiceNow ITOM incidents. Operations teams can preserve investigation context in Azure while managing ownership, escalation, and resolution through existing ServiceNow processes. This can reduce duplicate triage work and improve continuity between cloud monitoring and established IT service management workflows.

Quick Take: Azure teams should revisit architecture assumptions around AI models, cross-cloud networking, and log economics rather than treating each as an isolated service update.

Agent 365

Agent 365: Governance and Adoption Analytics Expand

Agent 365 is adding richer administrative visibility, usage reporting, interoperability, and centralized governance for enterprise agents.

  • Managers gain team-level Agent 365 analytics. Managers who already have team-level Copilot Analytics access in Viva Insights can see active agents, active users, sessions, and returning users for their teams. The worldwide rollout began in late August 2026, with access controlled through VFAM.
  • Company-level admins can export de-identified usage metrics. Beginning in September, administrators with full company-level access can export row-level metrics for custom reporting. This gives organizations additional ways to analyze agent adoption, usage patterns, and spend while reducing exposure of directly identifiable user-level information.
  • Agent Map adds centralized agent discovery. The Microsoft 365 admin center can group agents by platform and let administrators filter by status or publisher before drilling into individual agents. The capability requires an E7 or Agent 365 license and can help governance teams identify concentrations of agents across the environment.
  • Agent2Agent interoperability reaches Microsoft 365 Copilot. Agents published to Agent 365 that support the Agent2Agent protocol can be selected as connected agents in Microsoft 365 Copilot Chat and declarative agents. This supports more modular multi-agent architectures but also increases the importance of controlling which agents can interact.
  • Copilot connector governance has moved to Allowed agent types. The setFederatedConnectors CLI toggle retired on August 25, and connector controls now sit under the Allowed agent types setting in the Microsoft 365 admin center. Administrators relying on the retired control should confirm that their intended connector restrictions are represented in the new governance model.

Why It Matters: Agent adoption is shifting from experimentation toward a governed enterprise service that requires inventory, usage analytics, licensing oversight, and explicit controls over agent and connector interoperability.

Copilot

Copilot: New Models, Broader Automation, and Stronger Governance

Microsoft 365 Copilot is expanding across models, authoring surfaces, automation, grounding, analytics, and administration. The operational theme is clear: as Copilot gains access to more content and can take more actions, governance over billing, grounding data, retention, credentials, and agent availability becomes more important.

Models & Platform

  • Cowork adds configurable reasoning effort. Users can choose Light, Medium, High, Extra High, or Max effort to balance quality, speed, and credit consumption. Medium remains the default for everyday work, while higher settings give Cowork more room for complex analysis and consume credits more quickly.
  • Cowork local browser automation is generally available in Edge. Cowork can work across SaaS applications and internal portals while the user is signed in, expanding its capabilities beyond documents. Organizations should review the permissions and business processes exposed through authenticated browser sessions because agent actions can now span more operational surfaces.
  • Claude Fable 5.1 and GPT-6 Astra expand reasoning options. Claude Fable 5.1 is available in Copilot Cowork and Copilot Studio, while GPT-6 Astra has started rolling out across both environments. Teams should test model behavior, output quality, credit consumption, and data-governance requirements before standardizing reasoning-heavy workflows on a particular model.
  • The LegalZoom agent is available inside Copilot. Users can perform supported legal tasks without leaving the Microsoft 365 workflow. Organizations should still evaluate the handling of sensitive legal information and determine which tasks are appropriate for AI-assisted processing.
  • Microsoft Scout introduces an always-on personal agent. The Frontier preview can act across Microsoft 365 while remaining subject to organizational policies. Administrator enablement, Intune configuration, and GitHub Copilot licensing are required, making deployment an endpoint, licensing, and governance decision as well as an AI feature decision.
  • Organizations can centrally manage Copilot skills for PowerPoint. Reusable organization-specific skills can standardize common presentation workflows, preferred formats, and repeatable processes. Central management can help reduce inconsistent prompting and make approved approaches easier to reuse.
  • Users provisioned with Copilot Cowork can use it to build Microsoft managed apps with natural language. The apps are visible in the M365 admin center. Usage of the apps uses Copilot credits.

User Experience & Surfaces

  • Microsoft 365 Copilot is moving to a unified application. Microsoft is bringing personal and work accounts into a more consistent experience with a simplified application name, icon, and web address. Organizations should update training materials, support documentation, and user communications where existing guidance references older Copilot entry points.
  • Copilot Chat supports targeted work on selected answer content. Users can highlight a sentence, paragraph, or table and ask Copilot to work specifically on that selection, which is previewed in the prompt before submission. This makes refinement more precise and reduces the need to regenerate or rewrite an entire answer.
  • Chats and individual responses can be shared through read-only links. Recipients can review shared Copilot content and continue the conversation in their own chat while remaining subject to organizational controls. Organizations should consider how shared AI-generated content fits existing information-sharing and data-classification practices.
  • Answer cards can surface richer information directly in responses. Model-driven cards can display information such as weather, sports, finance, and images, while a Try again option lets users refine an answer without rebuilding the original prompt. This creates a more interactive Chat experience and reduces unnecessary prompting.
  • Copilot Chat can create send-ready Outlook drafts. Users can turn a Copilot response into an Outlook draft without manually copying the content between applications. This shortens the path from analysis or drafting to communication while keeping the workflow inside Microsoft 365.
  • Copilot in Word improves linked content, visual reuse, and change visibility. Copilot can insert and format linked text, use visuals from reference documents during drafting, and highlight the exact words changed instead of entire paragraphs. These improvements make AI-assisted editing easier to review while allowing approved source documents to contribute more directly to generated content.
  • Word document summarization is moving to the right-hand surface. The summary experience is shifting away from the top of the document. Users and support teams may need to adjust to the new location when working with document-level Copilot summaries.
  • Copilot in Excel adds workbook history analysis. Users can summarize how a workbook changed over time, identify who made edits, and get help undoing changes or restoring an earlier state. Recent chats can also be reopened from the pane menu, making it easier to continue earlier analysis.
  • The =COPILOT Excel function retires September 14. AI-assisted Excel capabilities will remain available through the Copilot side pane after the function is retired. Organizations using the function in established workflows should update documentation and user processes before the retirement date.
  • Copilot in PowerPoint adds interactive slides. Users can create full-slide visuals for complex concepts, timelines, comparisons, systems, and data. This can reduce manual presentation design effort while still requiring review for accuracy, brand consistency, and appropriate use of organizational data.
  • PowerPoint adds the Sharpen slide titles skill. Copilot can rewrite slide titles as clearer takeaway statements instead of generic topic labels. This can help presenters communicate the primary message of each slide more directly.
  • Copilot Notebooks now span lightweight and workspace experiences. Users can work in a streamlined notebook experience in the Copilot app or a more extensive workspace in OneNote, with synchronized content between them. Notebooks can also recommend relevant documents based on existing notebook content.
  • Copilot Notebooks support more technical source formats. Markdown, plain text, rich text, READMEs, wikis, logs, transcripts, and similar files can be added as grounding sources. This broadens their usefulness for technical teams that need Copilot to reason from operational documentation, project notes, or structured text.
  • OneNote Copilot Notebooks on Windows add multimodal recording. Users can capture audio, images, and notes together and receive Copilot-generated summaries and action items. Organizations should consider retention and sensitivity requirements when meeting or working-session content becomes part of a notebook.
  • Copilot Notebook is available in OneNote for Mac. Mac users gain an AI-powered workspace for organizing and analyzing notes. This helps make notebook-based Copilot workflows more consistent across desktop platforms.
  • Cowork scheduled tasks are now managed under Automations. The renamed experience brings scheduled and event-triggered tasks into a single location. Users can manage recurring and conditional agent work without navigating separate task experiences.
  • Agent Builder simplifies new-agent setup. Newly created agents have capabilities enabled by default, the knowledge-configuration experience is simpler, and Uploaded Files has been renamed Attachments. Existing agents are not affected, so administrators should expect some differences between older and newly created agents.

Data Access & Grounding

  • Copilot can reason over governed Power BI data. Chat and Cowork can answer natural-language questions using Power BI reports and semantic models, while existing row-level security continues to apply. This enables AI-generated trends and summaries from governed business data without removing the access restrictions already applied to the semantic model.
  • Copilot in OneDrive Web brings natural-language actions directly to files. Licensed users can find, understand, analyze, create, and act on OneDrive files without opening each file individually. Permissions, sensitivity labels, retention policies, and oversharing remain important because Copilot can now interact with a broader set of stored business content through natural language.
  • Self-service Copilot connectors expand external grounding. Users can securely connect external sources such as Jira and Confluence using their own credentials, subject to administrator controls. Connector governance is moving to the Allowed agent types setting in the Microsoft 365 admin center as the setFederatedConnectors command-line toggle retires.

Governance & Administration

  • Copilot Pages and Notebooks will be stored in OneDrive for Business. These artifacts will fall under existing OneDrive compliance, retention, and lifecycle controls. Compliance teams should explicitly include Copilot-created Pages and Notebooks when evaluating retention policies, eDiscovery searches, legal holds, deletion requirements, and information-protection coverage.
  • Admins gain more granular Copilot and agent usage exports. Administrators can export anonymized usage data for deeper reporting and can review GitHub Copilot AI Credit usage in the Consumption Dashboard. This provides additional visibility for adoption analysis, licensing decisions, and AI-cost governance.
  • Microsoft 365 Copilot service plans control grounding behavior. Service plans determine Premium or Basic grounding availability for licensed users, and disabling the applicable service plan also disables Personal Content Mode. Licensing or service-plan changes can therefore affect both feature availability and which organizational or personal content Copilot can use.

Analytics & Optimization

  • Cowork adds more transparent credit reporting through /cost. After a task completes, users can see the percentage of their monthly credit limit remaining, month-to-date credit consumption, and the date the allowance resets. This gives users and organizations more visibility into the cost impact of higher-effort AI workloads.
  • Agent 365 provides an Active Users export. The read-only report identifies users who interacted with agents during the previous 30 days, while managers can also access team-level adoption and usage views. These capabilities can support deployment monitoring and help identify where agent investment is generating active use.
  • Copilot Analytics Labs adds reusable measurement resources. Microsoft provides templates, code, prompts, and guidance for analyzing Copilot adoption, usage, impact, and return on investment. Organizations can use these resources to move beyond basic license-assignment metrics toward more meaningful adoption and value analysis.
  • Copilot Analytics expands across Microsoft 365 applications. Usage metrics increasingly cover the Copilot app, Edge, OneNote, Outlook, Word, Excel, and PowerPoint. This gives program owners a broader picture of where employees are using Copilot rather than viewing adoption through a single application.
  • SharePoint adds Copilot citation analytics. Tenants with more than 50 Copilot licenses can see how often documents, pages, and news posts are referenced by Microsoft 365 Copilot Chat. These insights can help organizations identify valuable knowledge sources, outdated content, and repositories that may require stronger ownership or governance.

Personalization

  • Reusable personal skills can work across SharePoint sites. Users can create a personal skill once and apply the same preferred format or repeatable process across multiple SharePoint sites. This reduces the need to rebuild common instructions for each location while making personalized workflows more portable.
  • Microsoft 365 Copilot Memory uses chat history for personalization. Copilot can use previous interactions to tailor future responses and provides refreshed user controls for managing saved memories. Organizations should account for personalization when developing internal guidance around sensitive, confidential, or regulated information.

What to Consider: Copilot is becoming an orchestration layer across files, browsers, business data, external connectors, automation, and personalized context. Governance programs should therefore focus less on a single Copilot application and more on identity, permissions, grounding sources, retention, legal hold, agent actions, licensing, and consumption controls across the broader Microsoft 365 ecosystem.

Copilot Studio

Copilot Studio: Harness-Powered Agents Move Into Production

Copilot Studio is shifting toward modular, reasoning-heavy, multi-agent architectures with deeper enterprise data access and governed document creation.

  • The GitHub Copilot harness is generally available for reasoning-heavy agents. The harness determines when to call models, what context to provide, and which tools or connected agents to use while allowing an agent to plan and adapt as it works. Usage is subject to pay-as-you-go consumption, making capacity and cost governance an important part of production design.
  • Skills provide reusable agent capabilities. Teams can package instructions into modular skills, attach them to multiple agents, and share them with colleagues. This supports standardization and reuse instead of rebuilding common operating logic agent by agent.
  • Primary agents can delegate to specialized agents. One agent can act as a front door and route specific requests to purpose-built agents. This modular design can improve specialization but requires clear authorization boundaries, ownership, and auditing across agent-to-agent interactions.
  • Workflows and MCP servers are generally available as tools. Harness-powered agents can call deterministic multistep workflows as well as Model Context Protocol servers. This gives agents access to more structured execution paths while increasing the importance of validating the tools and actions exposed to them.
  • Agents can use memory and Microsoft IQ. Harness-powered agents can maintain persistent context and reach emails, calendar events, files, Teams messages, and people information through Microsoft IQ. They can also create and edit Word, Excel, PowerPoint, and PDF files in a governed sandbox, widening both their productivity value and the scope of data administrators must protect.
  • File-based conversations are easier to manage. Users can attach files to conversations and view files created by agents during those conversations. This improves document-centric workflows but places additional importance on file permissions, retention, sensitivity labeling, and downstream sharing.
  • Autonomous agents can be shared in run-only mode. Makers can give users access to execute an autonomous agent without granting authoring permissions. The separation can reduce the risk of unauthorized design changes when an agent is deployed broadly.
  • Administrators can restrict maker-supplied credentials. A new control can prevent makers from providing their own credentials for agent authentication, helping organizations enforce end-user authentication where required. This supports stronger identity separation and reduces the risk of shared maker credentials unintentionally granting broad access.
  • Legacy agent identities can migrate to Microsoft Entra Agent ID. Copilot Studio agents created before May may still use older application-registration identities and can be migrated through Power Platform Advisor. Identity teams should inventory older agents and determine whether migration is necessary to align with the newer governance model.
  • Copilot Tuning is moving to Copilot Studio skills. Agent Builder tuning templates are transitioning to a skills-based architecture, and existing agents will continue functioning. Tuning itself will stop without automatic migration, so teams relying on customized tuned behavior need an explicit transition plan.

Quick Take: Production agent programs now need the same disciplines applied to enterprise applications: identity architecture, least privilege, reusable components, testing, cost monitoring, data governance, and lifecycle management.

Defender

Defender: AI Security, Unified Operations, and Policy Changes

Microsoft Defender updates this month span email security, endpoint response, identity monitoring, data protection, and unified security operations. Organizations should pay particular attention to prompt-injection defenses, the January 2027 Defender for Cloud Apps file-policy retirement, Android client requirements, expanded third-party Sentinel analytics, and upcoming unified RBAC changes.

Defender for Office 365

  • Prompt-injection protection extends email security to AI threats. Microsoft Defender for Office 365 can detect and quarantine malicious email content designed to manipulate AI assistants through prompt injection. As Copilot and other agents gain access to organizational messages, hostile instructions embedded in email become another attack path that security teams need to detect before AI systems process the content.

Defender For Cloud Apps

  • Defender for Cloud Apps file policies retire January 6, 2027. Organizations using file policies for data loss prevention or file governance must recreate applicable controls using Microsoft Purview DLP or auto-labeling. Security and compliance teams should inventory existing policies, protected data, workloads, enforcement actions, and alerting requirements early enough to confirm equivalent Purview coverage before the legacy controls disappear.

Defender For Endpoint

  • Automated investigation and response becomes part of always-on protection. Defender for Endpoint is integrating automated investigation and response directly into antivirus protection while removing manual triggering and the standalone automated investigation experience. Security operations teams should update analyst procedures, automation runbooks, and escalation processes that currently depend on manually initiated investigations.
  • Android devices require Defender version 1.0.9107.0101 or later. Organizations must update the Microsoft Defender for Endpoint Android application by mid-September to avoid disruption to mobile threat protection. Endpoint administrators should identify outdated installations through Intune or their mobile-device management platform and complete the upgrade before protection is affected.

Defender For Identity

  • A new health alert identifies missing domain controller network traffic. Defender for Identity can alert administrators when expected domain controller traffic is not being collected. Because identity detections depend on complete telemetry, this can help identify sensor, network, or collection failures before they become prolonged monitoring gaps.

Defender XDR & Microsoft Sentinel

  • Sentinel expands UEBA coverage for third-party security data. Preview behavior and anomaly analytics now support Fortinet FortiGate, Check Point, Zscaler, and AWS GuardDuty data. FortiGate alone gains more than 40 behavioral detections for activity such as rapid configuration changes, backups, certificate changes, and disruption of security services, giving SOC teams additional behavioral context across non-Microsoft platforms.
  • Unified Defender RBAC will be enabled automatically. Microsoft Defender unified role-based access control will consolidate permissions across Defender and Sentinel workloads and import existing roles before activation. Administrators should review imported permissions and validate least-privilege access because legacy role assignments may affect a broader set of security workloads once the unified model is active.
  • Purview DLP alerts become behaviors in Defender XDR by default. Microsoft will treat Microsoft Purview data loss prevention alerts as behaviors rather than standalone incident-queue items, reducing incident volume while retaining the underlying information in Advanced Hunting and Purview. SOC teams should update triage processes so analysts know where to locate and investigate DLP activity after the change.
  • The Data Security Triage Agent adds AI-assisted DLP investigation. The agent provides AI-generated summaries and categorizations for Microsoft Purview DLP alerts within Defender XDR. Because these alerts can involve sensitive, regulated, confidential, or legally relevant information, AI-assisted triage should support rather than replace required compliance investigations and escalation procedures.
  • Defender XDR adds a unified identity timeline. Analysts can review activities and alerts from multiple Microsoft security sources in a single chronological identity view. This can accelerate investigations where compromised accounts or credentials affect endpoints, cloud services, applications, or other protected workloads.
  • Microsoft Secure Score adds AI-readiness recommendations. New recommendations cover TPM 2.0, virtualization-based security, hypervisor-protected code integrity, and Windows Local Administrator Password Solution protections. These controls provide an endpoint-hardening baseline for organizations preparing devices and identities for broader AI-enabled access.

What To Consider: Microsoft Defender is becoming more consolidated across identity, endpoint, email, data security, and SIEM operations, which can simplify investigations but also increases the importance of consistent RBAC, telemetry health, and cross-team operating procedures. Organizations should prioritize the January 6, 2027 Defender for Cloud Apps migration, validate the mid-September Android client requirement, review unified Defender RBAC mappings, and ensure SOC workflows account for the changing treatment of Purview DLP alerts and AI-assisted security investigations.

Edge for Business

Edge for Business: Faster Releases and Security Platform Changes

Edge is accelerating its release cycle while deepening Copilot integration and retiring older Windows security technologies.

  • Edge Stable has moved to a two-week major release cadence. Version 152 began the new cadence on August 27. Organizations that require longer testing cycles for internal applications should evaluate Extended Stable instead of assuming the standard channel will provide sufficient validation time.
  • Microsoft 365 Copilot Chat gains richer Edge grounding. Copilot can summarize and use context across browser tabs, Microsoft 365 documents, and YouTube videos. This broadens the data that can influence a response and makes browser permissions, data classification, and user awareness increasingly important.
  • Windows Information Protection and Microsoft Defender Application Guard support are retiring from Edge. Organizations still relying on these capabilities, particularly on Windows 10, should migrate to Microsoft Purview and built-in Edge security controls. The transition should include validation of equivalent data-protection and browser-isolation requirements rather than a simple feature removal.

Quick Take: The browser is becoming both a faster-moving application platform and an AI context surface, so browser deployment rings and data protection policies should be reviewed together.

Entra

Entra: Tenant Governance Targets Multi-Tenant Complexity

Microsoft is positioning Entra Tenant Governance as a centralized layer for organizations managing multiple related tenants.

  • Tenant Governance centralizes discovery and configuration oversight. The service can help identify related tenants, monitor configuration drift, establish governance relationships, and support delegated administration. Basic configuration monitoring is available through existing Entra entitlements such as P1, while Premium capacity is licensed around administrators and additional governance scale rather than every user in every tenant.

Why It Matters: Multi-tenant organizations should evaluate governance based on administrative relationships and configuration consistency, not just user licensing counts.

Entra ID

Entra ID: Passkeys, Token Revocation, and Federation Hardening Accelerate

Entra ID is moving further toward phishing-resistant authentication while tightening federation behavior and enabling faster application-session revocation.

  • Passkey enrollment expands beginning September 1. Users enabled for SMS or voice authentication are being automatically enabled for passkeys and may be prompted to register one during MFA. Microsoft-provided SMS and voice authentication ends February 1, 2027, so organizations should accelerate migration toward stronger authentication methods.
  • Passkeys can be the first registered MFA method. Users can register a passkey or another passwordless sign-in method without first registering a weaker authentication method. This removes a deployment dependency that previously made stronger authentication onboarding more cumbersome.
  • Unused SMS first-factor sign-in can be disabled automatically. Entra ID will disable SMS as a first-factor sign-in method in tenants with no successful, or only unsuccessful, SMS sign-ins during the previous 30 days. SMS for MFA and password reset remains available, so administrators should distinguish first-factor authentication changes from broader SMS retirement planning.
  • Custom CSS branding capabilities are retiring. Entra ID will remove custom CSS layout and positioning properties used in company branding. Organizations with highly customized sign-in experiences should test their branding against supported alternatives before the legacy properties disappear.
  • Federated token validation defaults are becoming stricter. Entra ID will block federated sign-ins when the configured federation domain does not match the user principal name domain. Identity teams using complex federation configurations should validate domain mappings before the updated default creates unexpected authentication failures.
  • Identity self-service experiences are moving to cloud.microsoft. My Account and related Entra self-service experiences will transition to the cloud.microsoft domain. Network allowlists, security tooling, documentation, and user guidance may need updates where legacy domains are explicitly referenced.
  • Authenticator improves iOS passkey restoration. A guided device-migration experience is designed to make passkey restoration easier when users change iPhones. This can reduce support friction as passkey adoption increases.
  • Windows Hello for Business and macOS Platform SSO become standalone MFA factors. Entra ID recognizes both as independent multifactor authentication factors. This gives organizations more flexibility to build phishing-resistant access strategies across Windows and macOS fleets.
  • Continuous Access Evaluation can revoke application tokens immediately. Entra can now revoke service-principal bearer tokens before their normal expiration. Security teams gain a faster mechanism for stopping application access when an identity is compromised or should no longer be authorized.

What to Consider: The February 1, 2027 SMS and voice deadline should anchor a broader authentication modernization plan that also covers passkeys, federation dependencies, device-based authentication, and service-principal containment.

Entra Suite

Entra Suite: Conditional Access Expands Beyond Sign-In

Microsoft continues positioning Entra Suite as a unified Zero Trust platform spanning identity protection, governance, network access, and verified identity.

  • Entra Suite combines identity and network access controls. The suite brings Entra ID Protection and Governance together with Internet Access, Private Access, and Verified ID. Conditional Access is increasingly extending beyond authentication decisions into SaaS traffic, private applications, internet access, and broader network policy enforcement.
  • Global Secure Access is becoming a more credible VPN and secure-web-gateway alternative. Recent improvements support private application access, internet filtering, branch connectivity, and identity-aware policy enforcement. Organizations evaluating SSE or VPN modernization can now assess these capabilities alongside existing identity investments rather than as a separate network-security stack.

Quick Take: Conditional Access is becoming a policy engine for more than authentication, which creates an opportunity to converge identity and network security architectures.

Fabric

Fabric: OneLake Governance and Power BI Operations Mature

Microsoft Fabric is expanding native governance, secure connectivity, operational telemetry, AI integration, and Power BI development capabilities.

  • OneLake Catalog becomes the primary governance experience for Fabric-native data. Microsoft is bringing discovery, lineage, ownership, security visibility, and governance posture into OneLake Catalog. Purview remains the broader enterprise layer for classification, DLP, Insider Risk, Audit, compliance, and governance across Fabric, Microsoft 365, Azure, and other data sources.
  • Fabric Data Agents in Copilot Studio are generally available. Organizations can make governed Fabric business data available to Copilot Studio agents for questions and insight generation. Existing data permissions and governance remain important because agents can now use Fabric data directly as a trusted business source.
  • Workspace Outbound Access Protection enters preview. The capability supports the Operations Agent and Fabric Maps and allows workspace administrators to control outbound connections from Fabric items to external resources. This gives teams a new mechanism for reducing uncontrolled data egress from governed workspaces.
  • Capacity Operation Events arrive in Real-Time Hub preview. Fabric capacity administrators can access operation-level telemetry in near real time. The additional visibility can help identify performance or capacity problems while they are occurring rather than relying solely on after-the-fact analysis.
  • Fabric REST APIs add connection recency information. Administrators can see how recently Fabric connections were used, making it easier to identify stale shared connections. This can improve connection hygiene and reduce unnecessary credentials or integration paths.
  • Fabric Data Factory improves secure Snowflake connectivity. Pipelines and Copy jobs can connect to Snowflake in scenarios where public network access is restricted. This supports enterprise data-movement patterns that require tighter network controls.
  • Copilot Summary and Narrative can read visuals hidden behind bookmarks. AI-generated report summaries can incorporate a more complete view of report content. Report authors should verify that hidden or conditionally displayed visuals are appropriate for Copilot-generated narratives.
  • Fabric Apps have updated semantic model permission requirements. Power BI changed the permissions required for semantic models used by Fabric Apps. Administrators and report owners should review sharing configurations so consumers do not unexpectedly lose access.
  • A broad set of reporting enhancements is generally available. Improvements include modern visual defaults, theme customization, slicer date pickers, donut-chart center values, matrix column-header expand and collapse, OneLake file URLs for visuals and maps, chart padding controls, Azure Maps improvements, and new slicer formatting. The cumulative effect is greater author control over usability and presentation.
  • Power BI development and mobile workflows continue to improve. PBIP projects gain faster reload behavior and Visual Studio Code integration, while the mobile app adds report rotation and Excel export. SharePoint Online embedding and service-side semantic model refresh controls are also improving.
  • Direct Lake modeling adds new previews. Modelers can preview converting Direct Lake tables to Import mode through web modeling and can use Direct Lake calculated columns. These capabilities provide more flexibility when performance or modeling requirements differ from a pure Direct Lake approach.

Why It Matters: Fabric governance is becoming more native to OneLake without eliminating Purview, so organizations should define where Fabric-level stewardship ends and enterprise-wide compliance governance begins.

Intune

Intune: Remote Help Expands as Platform Requirements Tighten

Intune is adding unattended support capabilities while introducing several migration and operating-system requirements administrators should plan for.

  • Remote Help supports unattended Windows sessions. Authorized support staff can connect to eligible physical, corporate-owned, Intune-managed Windows devices without an end user being present and authenticate using their own credentials in a separate Windows session. RBAC and auditing are built into the process, while virtual devices, BYOD devices, and unenrolled devices are not supported. Review Microsoft’s Intune documentation.
  • Legacy app protection targeting must move to assignment filters. App protection policies using the Target to apps on all device types setting must migrate before January 11, 2027. Administrators should inventory affected policies and validate equivalent targeting before the legacy option is removed.
  • Future Intune releases raise Apple OS minimums. Intune will require iOS and iPadOS 18 or later after Apple releases iOS and iPadOS 27. New macOS enrollments will require macOS 15 or later after macOS Golden Gate 27 is released, making device lifecycle planning important for older Apple hardware.
  • Windows 365 User settings are moving to Cloud PC Settings. Existing User settings policies must be migrated into the unified Cloud PC Settings framework before they become read-only and are ultimately retired. Windows 365 administrators should compare current policy behavior before migration to avoid configuration drift.

What to Consider: The unattended Remote Help feature can materially improve support operations, but organizations should review technician RBAC, auditing, device eligibility, and privileged-access procedures before enabling it broadly.

OneDrive

OneDrive: Sync Reliability and Administrative Control Improve

OneDrive is improving large-path handling, macOS synchronization, and the balance between user-controlled file exclusions and centralized policy.

  • Windows sync errors are clearer for paths over 520 characters. OneDrive now directs users to rename or move affected files instead of stopping broader synchronization. This should reduce disruption in environments with deeply nested project or collaboration folders.
  • macOS receives a native synchronization engine. The new engine is designed to improve reliability, performance, and resource efficiency. Mac-heavy organizations should monitor rollout behavior and validate compatibility with endpoint security and file-management tooling.
  • File-level sync exclusions gain more flexible control. New policies can allow users to manage synchronization exclusions while still letting administrators restrict that capability. This gives enterprises more flexibility to balance user productivity with requirements around which files are synchronized to endpoints.

Quick Take: OneDrive changes increasingly affect endpoint operations and governance together, so sync behavior should be evaluated alongside retention, information protection, and local-device risk.

Outlook

Outlook: Sensitivity Labels Follow Attachments More Closely

Outlook is expanding sensitivity-label recommendations across platforms while introducing platform-specific capability and support changes.

  • New Outlook for Windows supports locally stored Office attachments. Users can attach locally stored Word, Excel, and PowerPoint files. Administrators should account for locally sourced content when designing information-protection and endpoint-data controls.
  • Outlook mobile can inherit or recommend sensitivity labels from attachments. On iOS and Android, messages can automatically receive or recommend a sensitivity label based on labels already applied to attached files. This helps reduce mismatches in which protected files are sent inside an inadequately classified email message.
  • Outlook for Mac receives similar label inheritance behavior. Messages can automatically apply or recommend Microsoft Purview sensitivity labels according to the classification of attached files. Compliance teams should validate label-priority and recommendation behavior for high-impact data classifications.
  • Outlook mobile signatures can use OneDrive-hosted images. Users on iOS and Android can insert signature images stored in OneDrive. Organizations with standardized branding may want to incorporate the capability into mobile email guidance.
  • Outlook for iOS requires iOS 26 or later beginning in mid-September. Organizations with older devices should identify affected users before the requirement takes effect. Unsupported endpoints could lose access to current Outlook capabilities or fall outside normal support expectations.

Why It Matters: Attachment-aware labeling helps carry data classification into the surrounding email, reducing a common gap between file protection and message protection.

Planner

Planner: Project Licensing and AI Status Reporting Change

Planner is absorbing more project and meeting workflows while organizations face an October licensing deadline.

  • Project Online Essentials reaches end of life October 1. Organizations must move affected users to a supported Project or Planner license. Licensing teams should identify dependent users and workloads before the cutoff rather than assuming functionality will automatically map to a replacement entitlement.
  • Teams meetings can connect to existing Planner plans. Tasks created around a meeting can live in an established shared plan instead of generating a separate planning space. This can reduce fragmented task tracking for recurring teams and project meetings.
  • Copilot adds AI-generated status reports and task improvements. Teams can generate written status views without manually assembling project updates. Managers should still validate generated summaries against the underlying plan when status information informs executive, customer, or compliance reporting.

What to Consider: The October 1 licensing deadline is an opportunity to consolidate fragmented Project and Planner usage rather than performing a one-for-one license replacement.

Power Platform

Power Platform: Desktop Automation and Copilot Actions Expand

Power Platform is reducing friction in desktop-flow design while creating tighter connections between cloud flows, Copilot Studio, and Power Apps.

  • Desktop flows can be scheduled without a separate cloud flow. The capability entered public preview in August and simplifies unattended automation architecture. Makers can reduce orchestration overhead for scenarios that previously required an extra flow solely for scheduling.
  • Desktop flows gain a flow-chart view in public preview. Makers can visualize a desktop flow as a diagram, making complex automation easier to understand and troubleshoot. This can improve maintainability for flows that have grown through multiple iterations or owners.
  • Integrated Power Apps forms are targeted for September general availability. Tighter Power Apps integration gives makers a more direct path from organizational data to a working form experience. Governance teams should continue applying environment, connector, and DLP controls as low-code development becomes easier.
  • Cloud flows can call Copilot Studio actions and desktop flows. This enables AI-assisted workflows to hand off work to deterministic automation for precise execution. The combination can be valuable for multi-step business processes where reasoning is needed to decide what should happen but controlled automation should perform the action.

Quick Take: The line between AI agents and traditional automation is narrowing, making environment strategy, connector governance, credentials, and execution auditing increasingly important.

Purview Information Protection

Purview Information Protection: Higher Labeling Scale and New Retention Controls

Purview is taking on additional data-protection responsibilities while expanding labeling scale, deletion workflows, retention logic, PST ingestion, and label propagation.

  • Auto-labeling scales to 500,000 SharePoint and OneDrive files per day. The previous limit was 100,000 files per day. Microsoft is positioning the increase partly around accelerating classification before broad Copilot adoption, which can help organizations protect sensitive content before exposing larger repositories to AI-assisted discovery and grounding.
  • Defender for Cloud Apps file policies retire January 6, 2027. Organizations using those policies for DLP must migrate applicable controls to Purview DLP or auto-labeling. Migration planning should preserve coverage of protected files, policy conditions, alerts, and remediation actions across the workloads involved.
  • Priority cleanup supports permanent deletion of selected SharePoint and OneDrive content. The workflow can delete content even when it is subject to retention or legal hold, but only after required eDiscovery approval. Because this can override normal retention protections, organizations should restrict access tightly and ensure legal, records-management, and audit procedures govern its use.
  • Azure PST Import supports Exchange Online ingestion. Administrators can import PST files from Azure Blob Storage into Exchange Online mailboxes through PowerShell with readiness validation, reporting, and auditing. The workflow is relevant to migration, archival, and legal-data scenarios where PST content needs to enter governed Exchange Online mailboxes.
  • Retention policies can use the last-accessed date. Purview can apply retention logic to OneDrive and SharePoint files based on when content was last accessed. Records managers should evaluate whether access-based retention aligns with legal and regulatory requirements before replacing creation-date or modification-date models.
  • Sensitivity labels can propagate from attachments to Outlook messages. Outlook mobile and Outlook for Mac can apply or recommend labels based on labeled attachments. This can help maintain protection when sensitive documents move into email workflows.

Why It Matters: Purview is becoming the destination for more file-governance controls, and several new capabilities directly affect protected SharePoint, OneDrive, Exchange, retention, legal hold, and eDiscovery data.

SharePoint Online

SharePoint Online: Classic Experiences Retire as AI Authoring Expands

SharePoint continues its move away from classic publishing while introducing AI-assisted authoring, usage analytics, and new storage billing options.

  • Classic publishing sites and user-created classic pages are entering retirement. Microsoft plans to disable creation of new classic publishing sites and pages, make existing pages read-only, and disable custom scripting. Organizations with legacy intranets or custom publishing solutions should inventory dependencies before these controls limit editing or customization.
  • AI-powered page authoring is planned but currently paused. SharePoint page editors with Microsoft 365 Copilot licenses are expected to gain a natural-language authoring panel for creating and editing pages. Because rollout is paused, organizations should avoid basing near-term deployment plans on immediate availability.
  • SharePoint storage overages can use Azure pay-as-you-go billing. Organizations can choose usage-based billing instead of relying solely on fixed manual storage purchases. Finance and platform teams should establish monitoring and ownership before enabling consumption-based overage billing.
  • Copilot citation analytics expose frequently referenced content. Tenants with more than 50 Copilot licenses can see how often documents, pages, and news posts contribute to Microsoft 365 Copilot Chat responses. Content owners can use this to identify high-value knowledge as well as material that may need stronger ownership, freshness, or governance.

What to Consider: SharePoint modernization should address both sides of the platform: retiring classic dependencies and improving governance of the modern content Copilot increasingly uses as organizational knowledge.

Teams

Teams Chat & Channels — Smarter Notifications + Stronger External Controls
  • Channel notification management becomes more centralized. Teams is bringing channel notification controls into one location and adding presets for all new messages, mentions and replies, muted channels, and temporary notification pauses. This should make high-volume Teams environments easier for users to organize without requiring them to configure each channel individually.
  • Teams workflows support multiple sequential actions. Users building workflows from scratch can now add multiple actions in sequence instead of limiting a workflow to a single action. This expands lightweight automation directly inside Teams and can reduce the need to move simple collaboration processes into separate automation experiences.
  • External messaging restrictions are coming for onmicrosoft.com-only tenants. Organizations using only an onmicrosoft.com domain will be subject to outbound external Teams-message limits designed to reduce spam and abuse. Administrators should evaluate external collaboration requirements and domain configuration if business processes depend heavily on communicating with external Teams users.
  • Teams web is moving to teams.cloud.microsoft. Web users will be redirected to the new teams.cloud.microsoft domain. Organizations should review network allowlists, security controls, bookmarks, user documentation, and other configurations that explicitly reference the current Teams web address.
Teams Meetings & Conferencing — More Meeting AI + Stronger Security and Compliance Controls
  • Breakout rooms scale to larger meetings. Teams breakout rooms can support meetings with up to 1,000 attendees and as many as 100 rooms. This gives organizations more capacity for large training sessions, workshops, conferences, and structured collaboration events, but meeting owners should ensure moderation and facilitation processes can scale with the higher limits.
  • External meeting-assistant bots are identified before joining. Teams will identify and label external meeting-assistant bots when they attempt to enter a meeting, giving organizers the ability to approve, deny, or remove them. This provides greater visibility into third-party AI assistants, recording tools, and other services that could otherwise gain access to meeting conversations and content.
  • Facilitator expands into channel meetings. Facilitator can join channel meetings to take notes, manage agendas, answer questions, and handle tasks during the meeting. It can also identify knowledge gaps, search the web, and post relevant answers in meeting chat, which increases its usefulness while making governance of externally sourced information more important.
  • Meeting AI archives are stored in tenant-owned SharePoint. AI-generated meeting insights used to improve Copilot and Facilitator responses will be stored in SharePoint under the organization’s control. The archives do not contain raw meeting content and are not directly accessible to users, but administrators should still account for their storage, retention, compliance, lifecycle, and legal discovery implications.
  • Instant meetings gain persistent meeting notes. Notes for instant meetings can be captured using Loop components and remain available after the meeting through Recap. This means unscheduled meetings can generate persistent collaborative content that may fall under the same retention, access, and compliance requirements as scheduled meeting artifacts.
  • The Teams Recap app centralizes post-meeting content. Recordings, transcripts, AI-generated summaries, and other recap information from recent meetings are brought together into a dedicated experience. Because these artifacts may contain sensitive business, customer, employee, or regulated information, organizations should review permissions, retention policies, sensitivity controls, and sharing behavior.
  • Meeting AI gets a meeting-level control. Licensed organizers and presenters can turn Copilot and Facilitator on or off for an individual meeting. Turning off Meeting AI also disables recording and transcription, so organizations should understand that the control affects the broader meeting-recording and compliance workflow rather than AI capabilities alone.
  • Teams can require participant consent before meeting entry. Organizations can configure custom terms that participants must accept before joining a meeting, with acceptance recorded in audit logs. This can support meetings involving confidentiality requirements, regulated interactions, legal acknowledgments, or other scenarios where documented consent is important.
  • Structured meetings gain a private presenter chat. Organizers, co-organizers, and presenters can privately communicate during webinars, town halls, and other structured meetings. This gives event teams a dedicated coordination channel without exposing operational conversations to attendees.
  • Users can report suspicious meeting activity. Teams is adding a Report a concern option for suspicious behavior such as phishing or scams during meetings. Security teams should determine how these reports are monitored, investigated, and incorporated into existing incident-response workflows.
  • The profanity filter for live captions will be disabled by default. Users can choose to turn the filter back on individually. Organizations with accessibility, education, HR, legal, or regulated communications requirements should determine whether internal guidance is necessary around the changed default.
  • Meeting controls and screen sharing receive a redesign. Teams is introducing centered meeting controls, a separated Leave button, customizable actions, and a two-step confirmation before sharing content. The added confirmation can help reduce accidental screen sharing, which is particularly important when presenters may have sensitive or confidential information open on their devices.
Teams Phone — AI-Powered Calls + More Flexible Mobile Calling
  • AI-powered interpretation expands to supported Teams Phone devices. Users with Microsoft 365 Copilot licenses can access AI-powered interpretation on supported Teams Phone hardware. Organizations evaluating the feature should confirm device compatibility, licensing requirements, supported languages, and any compliance implications associated with AI processing of voice communications.
  • Queue calls gain Copilot and intelligent call recap. Recorded queue calls can produce AI-generated summaries, key points, follow-up actions, and question-and-answer capabilities. Because recordings and generated summaries can contain customer, employee, financial, healthcare, or other sensitive information, organizations should review recording consent, retention, access, and data-protection requirements before enabling the capability broadly.
  • Teams mobile supports multiple phone lines. Mobile users can select between phone lines, return calls using the appropriate line, and see activity in a unified call history. This can simplify mobile workflows for employees managing multiple departmental, business, or organizational numbers.
Teams Premium — More Event Customization + Copilot Licensing Requirements
  • Teams Premium town halls add custom backgrounds. Organizers and presenters can upload custom background images for supported town-hall layouts. This gives organizations more branding and presentation control for large internal or external events.
  • Copilot-based queue call recap requires multiple licenses. The Teams Queues app requires Teams Premium together with Microsoft 365 Copilot for Copilot-powered call recap capabilities. Organizations considering AI-assisted queue-call workflows should evaluate both licensing requirements and the data-governance implications of recording and summarizing customer or employee conversations.

Windows

Windows: 26H2 Arrives as Support and Security Deadlines Approach

Windows administrators face a new feature release, approaching support deadlines, Secure Boot work, management changes, and a September restart requirement.

  • Windows 11 26H2 has entered Release Preview. Organizations can begin validation ahead of broader deployment while Windows 11 23H2 Enterprise and Education reach end of support on November 10. Device-management teams should align application testing and update rings with the support deadline.
  • The 2026 Secure Boot certificate transition continues. Organizations should ensure device fleets are prepared for updated Secure Boot certificates. Environments with older AD FS infrastructure should also review manual hardening requirements introduced in the August security update.
  • Windows 11 settings backup becomes enabled by default on eligible devices. Administrators can explicitly configure a different setting, while restore remains administrator-controlled and disabled by default. Organizations should assess whether backup behavior aligns with endpoint, privacy, and configuration-management policies.
  • Windows Autopatch expands update-management controls. The service adds management options for Windows quality updates, supported .NET Framework updates, and quick machine recovery updates. This gives administrators more ways to standardize update execution through the Autopatch service.
  • Windows Server 2022 leaves mainstream support October 13. The platform transitions to extended support and will continue receiving monthly security updates. Infrastructure teams should account for the support phase change in lifecycle planning even where immediate server replacement is not required.
  • September’s Windows security update requires a restart on hotpatch-enabled devices. The update is being delivered as a standard update rather than a hotpatch release. Operations teams should plan maintenance windows accordingly instead of assuming eligible devices will avoid a restart.
  • The WMIC command-line utility is removed from Windows 11 24H2 and later. Windows Management Instrumentation itself remains supported. Scripts and administrative workflows that call wmic.exe should migrate to supported alternatives such as PowerShell-based WMI or CIM commands.

What to Consider: November’s Windows 11 support deadline, October’s Windows Server lifecycle change, Secure Boot certificate work, and WMIC removal should be tracked as one endpoint and infrastructure readiness program rather than as unrelated updates.

Get in Touch with Us

Connect with an expert to learn what we can do for your business.

One More Step!

Your Win Wires registration is complete. Request Microsoft access to open the customer documents.

Access may take a few minutes to activate.
After completing the Microsoft access request, there may be a short delay before you can open Win Wire files.

Use the same work email you registered with. Microsoft access is only requested once, unless it expires or is revoked.

Get Access to Win Wires

Enter your name and work email to set up your Win Wires account.

Next, you’ll request access to the Win Wires documents through Microsoft. You’ll only need to complete registration once.

October 21, 2026 • Cloud, AI, and Security Virtual Workshop • 1–5 PM ET