Four Critical CVEs land across Azure AD B2C, Copilot Studio, Azure AI Language, and Microsoft Fabric - plus GPT-6 Astra and Claude Fable 5.1 go live in Copilot, and Exchange hybrid shops face a hard version-floor deadline starting this week.
Autopilot device association reaches GA with hardware-backed pre-enrollment trust, Remote Help gets unattended Windows access, and two Critical-severity CVEs land alongside a heads-up from Exchange Online that legacy identifier properties may be on their way out.
Official Microsoft deployment and setup guides for Intune, Defender, Entra, Copilot, Purview, and Viva, organized by Modern Work practice area, plus what actually changes across Commercial, GCC, GCC High, and DoD.
New to Modern Work Weekly? This is the map: what the site covers, the three ways to read it, why everything is organized around six pillars, and how to actually navigate it.
A plain definition of Modern Work: Microsoft's practice areas spanning identity, endpoints, collaboration, AI, employee experience, and security, explained for engineers and executives.
Exchange Server SE gets its August security updates while CU1 slips further, and a wave of CVE acknowledgment updates signals an active patch cycle. Engineers also get new Defender for Identity tooling, granular Purview audit logs on the horizon, and a useful roundup of Windows device recovery options.
Entra Tenant Governance hits GA for multi-tenant control at scale, Defender for Identity expands sensor v3.x coverage to AD FS, AD CS, and Entra Connect, and the Copilot Domain Exclusion feature gets quietly rolled back - a lot moved this week.
Defender for Office 365 Plan 1 lands in M365 E3, Writeback for Cloud-Managed Remote Mailboxes hits GA, and Midnight Blizzard is actively targeting hospitality sign-in portals - a rich week of capability unlocks alongside real threat intelligence to act on.
Passkeys become the default in Entra ID, Entra Backup and Recovery hits GA, and advanced Intune Suite capabilities land in M365 E3/E5 - a dense week for identity hardening and endpoint licensing.
A light data week dominated by MSRC vulnerability disclosures for gawk and node-tar, plus an OWA Light retirement announcement that Exchange Server admins need to plan for.
Copilot Cowork goes GA worldwide with Claude Sonnet 5 and Sales Agent in tow, while five new CVEs land in AI and TLS libraries that may touch your supply chain.
Six CVEs land across libxml2, GNU gzip, attr, and acl for Linux-adjacent workloads, Intune's June release doubles down on AI-era endpoint hygiene, and a malicious Chromium extension spoofing Perplexity AI is actively redirecting browser search. EWS retirement remains on track for its October 2026 deadline.
EWS retirement hits its final phase with a hard October 2026 deadline, Intune Suite advanced capabilities land in M365 E3/E5 by August 1, and three Entra ID legacy auth controls are heading for retirement — this week is heavy on deadlines and migration obligations.
Entra Tenant Governance surfaces shadow tenants, Purview DSPM for AI hits GA, and computer-using agents in Copilot Studio are production-ready — a feature-dense week with meaningful capability unlocks across identity, data, and automation.
CVE-2026-42897 demands immediate patch action on all on-prem Exchange deployments, while Teams Live Events hits its June 30 retirement deadline — but this week also delivers real capability unlocks across AI agent governance, Purview posture reporting, and Entra multi-tenant visibility.
Global Secure Access hits a GA trifecta this week with iOS client, cloud firewall for remote networks, and file-type content filtering all shipping. Pair that with Purview DLP sync dropping from 2 hours to 30 minutes and the Intune Data Warehouse v1 connector retirement, and there's real work to do.