The Week at a Glance
- 🔴 High — Exchange Web Services retires in October 2026. Any business application, integration, or third-party tool still using this legacy email API will stop working. A four-month window remains, but audit and vendor coordination must start now.
- 🔴 High — Microsoft Entra ID is retiring legacy authentication controls. Organizations that rely on older multi-factor authentication customizations or self-service password reset configurations must begin migration planning or risk gaps in access enforcement that auditors and cyber insurers will flag.
- 🟡 Medium — Advanced device management capabilities arrive free in Microsoft 365 E3 and E5 on August 1. Licensing changes take effect July 1; organizations should plan to activate and configure these capabilities before employees encounter them unmanaged.
- 🟢 Low — SharePoint is receiving a visual refresh, and Teams Phone now supports AI voice agents. These are user-facing changes that benefit from proactive communication but require no urgent decisions.
Sources: Exchange Team Blog · Microsoft Entra Blog · Microsoft Intune Blog
Why This Week Matters
Two hard deadlines are converging this fall. The retirement of a widely used legacy email connectivity protocol in October 2026 will silently break business applications that no one has touched in years, including integrations with ERP systems, ticketing platforms, and automated reporting tools. Simultaneously, Microsoft is closing authentication policy gaps in Entra ID that attackers have exploited specifically because legacy controls allowed inconsistent enforcement.
The one thing leadership must understand: both items require your IT team to audit what you currently have in production before a remediation path can even be scoped. Neither fix is automatic, and neither vendor can do it for you. Starting the conversation this week protects the October deadline.
Sources: Exchange Team Blog · Microsoft Entra Blog · Microsoft Security Blog
Risk & Compliance
| Change | Business Risk | Regulatory Angle | Act By |
|---|---|---|---|
| EWS Retirement — Final Phase with EWSAllowedAppIDs allow-list | Business applications, automated workflows, and third-party integrations using this legacy email protocol will fail when Microsoft disables it. Revenue-impacting systems may go dark without warning. | SOC 2 availability controls; HIPAA covered entities using email-based health data workflows; CMMC organizations with automated reporting pipelines | Begin audit immediately; hard cutoff October 2026 |
| Entra ID Security Updates — Legacy MFA controls and SSPR policy retirement | Retirement of Custom Controls for MFA and inconsistent Conditional Access enforcement during credential registration creates windows attackers can exploit. Existing configurations continue during transition but must be migrated. | NIST CSF identity controls; cyber insurance MFA verification requirements; HIPAA access management; CMMC Level 2 multi-factor requirements | Migration planning should begin now; monitor Microsoft’s retirement timeline communications |
| Critical Office for Mac Vulnerabilities — CVE-2026-45469 and CVE-2026-45475 | Remote code execution vulnerabilities in Microsoft Excel and Office for Mac. Any unpatched Mac running Office is exposed to attacker-controlled code execution. | SOC 2 vulnerability management; cyber insurance patch compliance requirements; NIST CSF Protect function | Patch immediately; updates are available now |
| Advanced Intune Suite Capabilities Added to M365 E3 and E5 | Without deliberate activation and configuration, new device management capabilities may arrive in tenants in an unconfigured state, potentially creating policy gaps or user confusion. | CMMC device management controls; HIPAA device security requirements; NIST CSF asset management | Configure before August 1, 2026 |
| AI-Accelerated Cyberattacks Targeting Identity | AI tooling has lowered the cost and time required for credential-based attacks. Organizations with incomplete MFA coverage or stale Conditional Access policies face elevated and measurable exposure. | NIST CSF; SOC 2 CC6; cyber insurance identity verification attestations | Ongoing; review posture now alongside Entra ID migration work |
Sources: Exchange Team Blog · Microsoft Security Response Center · Microsoft Entra Blog
What Your Employees Will Notice
- SharePoint looks different. Microsoft has rolled out a visual refresh across SharePoint, reducing visual clutter and improving readability. Employees will see cleaner navigation and updated layouts. Branding investments organizations have made are preserved. Proactively communicate this is intentional, not a problem.
- Teams Phone now offers AI-assisted call handling. Organizations using Teams Phone can deploy AI voice agents to handle customer calls during high-volume periods, after hours, and on weekends. Customer-facing staff should be briefed on how these agents present to callers and where handoffs to human agents occur.
- Copilot gets more capable. The Microsoft 365 Copilot app now includes Copilot Cowork, which can handle multi-step tasks and longer-horizon work. Users with Copilot licenses will see a redesigned interface with a toggle between everyday chat and deeper task execution.
- Mac users need to update Office. Employees running Microsoft Office on a Mac should be prompted or instructed to apply available security updates immediately. This is not optional.
Sources: SharePoint Blog · Microsoft Teams Blog · Microsoft 365 Copilot Blog
What Your Help Desk Should Expect
- “SharePoint looks broken” tickets. The visual refresh will generate confusion from employees who notice layout and design changes and assume something is wrong. Prepare a one-paragraph communication that the change is intentional and link to Microsoft’s summary.
- Mac Office update prompts and failures. Following the remote code execution patch releases, IT should push updates to managed Macs and anticipate tickets from unmanaged or personally owned Macs where users are prompted to update but encounter errors.
- Copilot interface questions. The redesigned Copilot app and the new Cowork toggle will generate orientation questions from licensed users unfamiliar with the updated layout.
- Authentication and sign-in disruptions. As Entra ID legacy control retirements progress, some users may encounter unexpected MFA prompts or SSPR behavior changes if migration is not carefully sequenced. Help desk teams should be briefed on the Entra changes before users begin calling.
- Teams Phone and AI agent questions. Customer-facing staff and their managers will likely have questions about when an AI agent is handling calls and how escalation works.
Sources: SharePoint Blog · Microsoft Entra Blog · Microsoft Security Response Center
Cost & Licensing
- Free capability upgrade in existing licenses. Starting July 1, advanced capabilities from the Microsoft Intune Suite — previously requiring a separate add-on purchase — are included in Microsoft 365 E3 and E5 at no additional cost. These capabilities cover advanced endpoint analytics, remote help, and specialized device management scenarios. Organizations currently paying for the Intune Suite add-on should review whether their separate license remains necessary and may be eligible to reduce spend. Organizations not using these features should plan deliberate activation rather than letting them arrive unmanaged on August 1.
- Forrester Total Economic Impact data point for budget conversations. A newly published Forrester study found that organizations consolidating their security tooling onto Microsoft Security achieved a 124% ROI. For organizations currently evaluating point security products alongside Microsoft’s native capabilities, this provides externally validated benchmarking data for budget discussions.
Sources: Microsoft Intune Blog · Microsoft Security Blog — Forrester TEI Study
Planning Horizon
| Timeframe | Item | Decision or Action Required |
|---|---|---|
| July 1, 2026 | Intune Suite Capabilities Included in M365 E3/E5 — Licensing Change Effective | IT leadership should confirm whether existing Intune Suite add-on licenses can be retired; finance should adjust renewal forecasts |
| August 1, 2026 | Intune Suite Capabilities Arrive in Tenant | IT must have configuration decisions made before capabilities activate; no-action risks unconfigured features in production |
| August 2026 | Teams Meeting Bot Blocking Controls GA | Security and compliance teams should decide policy on external AI bots in meetings before the admin control is available; decisions benefit from legal and HR input |
| October 2026 | Exchange Web Services (EWS) Disabled in Exchange Online | Full application and integration audit required; vendor coordination for any third-party tools; migration to Microsoft Graph API may require development budget and IT project time |
| Ongoing — 30 days | Entra ID Authentication Control Migration | IT security team must inventory current Custom Controls for MFA and SSPR configurations and present a migration plan; executive sponsor may be needed to prioritize this work alongside other IT demand |
| Ongoing — 30 days | Windows 11 Version 26H2 Readiness | IT teams managing Windows endpoints should review readiness guidance now; no hard deadline yet, but early testing reduces deployment risk during annual update cycle |
Sources: Exchange Team Blog · Microsoft Intune Blog · M365 Roadmap
If You Take No Action
Exchange Web Services retirement (October 2026): Business applications and integrations that have never been catalogued and migrated will stop delivering data when Microsoft disables EWS. The failure mode is silent until something breaks: automated reports stop arriving, ticketing integrations stop syncing, finance or HR workflows stop processing. Identifying these integrations requires internal audit time that cannot be compressed into the final weeks before the deadline. Organizations without a current inventory of API-based integrations should treat this as their most urgent IT project for the next 60 days.
Entra ID legacy authentication control retirement: Gaps in Conditional Access enforcement and inconsistent MFA application create specific, auditable vulnerabilities. Cyber insurers increasingly require evidence of consistent MFA enforcement across all authentication paths during policy renewal. Organizations still using Custom Controls for MFA that have not migrated to the supported replacement may face findings in their next SOC 2 audit or questions from their insurer. The risk compounds because attackers are actively using AI to accelerate credential-based intrusions, as Microsoft’s own threat intelligence confirms this week.
Office for Mac vulnerabilities unpatched: Any Mac running an unpatched version of Office for Mac is exposed to remote code execution, meaning an attacker can run arbitrary code on that machine by getting a user to open a crafted file. In environments where Macs are unmanaged or on a manual update cycle, this exposure may persist for weeks. The patch is available now.
Sources: Exchange Team Blog · Microsoft Entra Blog · Microsoft Security Response Center
