The Week at a Glance

  • 🔴 High — Exchange Web Services retires in October 2026. Any business application, integration, or third-party tool still using this legacy email API will stop working. A four-month window remains, but audit and vendor coordination must start now.
  • 🔴 High — Microsoft Entra ID is retiring legacy authentication controls. Organizations that rely on older multi-factor authentication customizations or self-service password reset configurations must begin migration planning or risk gaps in access enforcement that auditors and cyber insurers will flag.
  • 🟡 Medium — Advanced device management capabilities arrive free in Microsoft 365 E3 and E5 on August 1. Licensing changes take effect July 1; organizations should plan to activate and configure these capabilities before employees encounter them unmanaged.
  • 🟢 Low — SharePoint is receiving a visual refresh, and Teams Phone now supports AI voice agents. These are user-facing changes that benefit from proactive communication but require no urgent decisions.

Sources: Exchange Team Blog · Microsoft Entra Blog · Microsoft Intune Blog


Why This Week Matters

Two hard deadlines are converging this fall. The retirement of a widely used legacy email connectivity protocol in October 2026 will silently break business applications that no one has touched in years, including integrations with ERP systems, ticketing platforms, and automated reporting tools. Simultaneously, Microsoft is closing authentication policy gaps in Entra ID that attackers have exploited specifically because legacy controls allowed inconsistent enforcement.

The one thing leadership must understand: both items require your IT team to audit what you currently have in production before a remediation path can even be scoped. Neither fix is automatic, and neither vendor can do it for you. Starting the conversation this week protects the October deadline.

Sources: Exchange Team Blog · Microsoft Entra Blog · Microsoft Security Blog


Risk & Compliance

ChangeBusiness RiskRegulatory AngleAct By
EWS Retirement — Final Phase with EWSAllowedAppIDs allow-listBusiness applications, automated workflows, and third-party integrations using this legacy email protocol will fail when Microsoft disables it. Revenue-impacting systems may go dark without warning.SOC 2 availability controls; HIPAA covered entities using email-based health data workflows; CMMC organizations with automated reporting pipelinesBegin audit immediately; hard cutoff October 2026
Entra ID Security Updates — Legacy MFA controls and SSPR policy retirementRetirement of Custom Controls for MFA and inconsistent Conditional Access enforcement during credential registration creates windows attackers can exploit. Existing configurations continue during transition but must be migrated.NIST CSF identity controls; cyber insurance MFA verification requirements; HIPAA access management; CMMC Level 2 multi-factor requirementsMigration planning should begin now; monitor Microsoft’s retirement timeline communications
Critical Office for Mac Vulnerabilities — CVE-2026-45469 and CVE-2026-45475Remote code execution vulnerabilities in Microsoft Excel and Office for Mac. Any unpatched Mac running Office is exposed to attacker-controlled code execution.SOC 2 vulnerability management; cyber insurance patch compliance requirements; NIST CSF Protect functionPatch immediately; updates are available now
Advanced Intune Suite Capabilities Added to M365 E3 and E5Without deliberate activation and configuration, new device management capabilities may arrive in tenants in an unconfigured state, potentially creating policy gaps or user confusion.CMMC device management controls; HIPAA device security requirements; NIST CSF asset managementConfigure before August 1, 2026
AI-Accelerated Cyberattacks Targeting IdentityAI tooling has lowered the cost and time required for credential-based attacks. Organizations with incomplete MFA coverage or stale Conditional Access policies face elevated and measurable exposure.NIST CSF; SOC 2 CC6; cyber insurance identity verification attestationsOngoing; review posture now alongside Entra ID migration work

Sources: Exchange Team Blog · Microsoft Security Response Center · Microsoft Entra Blog


What Your Employees Will Notice

  • SharePoint looks different. Microsoft has rolled out a visual refresh across SharePoint, reducing visual clutter and improving readability. Employees will see cleaner navigation and updated layouts. Branding investments organizations have made are preserved. Proactively communicate this is intentional, not a problem.
  • Teams Phone now offers AI-assisted call handling. Organizations using Teams Phone can deploy AI voice agents to handle customer calls during high-volume periods, after hours, and on weekends. Customer-facing staff should be briefed on how these agents present to callers and where handoffs to human agents occur.
  • Copilot gets more capable. The Microsoft 365 Copilot app now includes Copilot Cowork, which can handle multi-step tasks and longer-horizon work. Users with Copilot licenses will see a redesigned interface with a toggle between everyday chat and deeper task execution.
  • Mac users need to update Office. Employees running Microsoft Office on a Mac should be prompted or instructed to apply available security updates immediately. This is not optional.

Sources: SharePoint Blog · Microsoft Teams Blog · Microsoft 365 Copilot Blog


What Your Help Desk Should Expect

  • “SharePoint looks broken” tickets. The visual refresh will generate confusion from employees who notice layout and design changes and assume something is wrong. Prepare a one-paragraph communication that the change is intentional and link to Microsoft’s summary.
  • Mac Office update prompts and failures. Following the remote code execution patch releases, IT should push updates to managed Macs and anticipate tickets from unmanaged or personally owned Macs where users are prompted to update but encounter errors.
  • Copilot interface questions. The redesigned Copilot app and the new Cowork toggle will generate orientation questions from licensed users unfamiliar with the updated layout.
  • Authentication and sign-in disruptions. As Entra ID legacy control retirements progress, some users may encounter unexpected MFA prompts or SSPR behavior changes if migration is not carefully sequenced. Help desk teams should be briefed on the Entra changes before users begin calling.
  • Teams Phone and AI agent questions. Customer-facing staff and their managers will likely have questions about when an AI agent is handling calls and how escalation works.

Sources: SharePoint Blog · Microsoft Entra Blog · Microsoft Security Response Center


Cost & Licensing

  • Free capability upgrade in existing licenses. Starting July 1, advanced capabilities from the Microsoft Intune Suite — previously requiring a separate add-on purchase — are included in Microsoft 365 E3 and E5 at no additional cost. These capabilities cover advanced endpoint analytics, remote help, and specialized device management scenarios. Organizations currently paying for the Intune Suite add-on should review whether their separate license remains necessary and may be eligible to reduce spend. Organizations not using these features should plan deliberate activation rather than letting them arrive unmanaged on August 1.
  • Forrester Total Economic Impact data point for budget conversations. A newly published Forrester study found that organizations consolidating their security tooling onto Microsoft Security achieved a 124% ROI. For organizations currently evaluating point security products alongside Microsoft’s native capabilities, this provides externally validated benchmarking data for budget discussions.

Sources: Microsoft Intune Blog · Microsoft Security Blog — Forrester TEI Study


Planning Horizon

TimeframeItemDecision or Action Required
July 1, 2026Intune Suite Capabilities Included in M365 E3/E5 — Licensing Change EffectiveIT leadership should confirm whether existing Intune Suite add-on licenses can be retired; finance should adjust renewal forecasts
August 1, 2026Intune Suite Capabilities Arrive in TenantIT must have configuration decisions made before capabilities activate; no-action risks unconfigured features in production
August 2026Teams Meeting Bot Blocking Controls GASecurity and compliance teams should decide policy on external AI bots in meetings before the admin control is available; decisions benefit from legal and HR input
October 2026Exchange Web Services (EWS) Disabled in Exchange OnlineFull application and integration audit required; vendor coordination for any third-party tools; migration to Microsoft Graph API may require development budget and IT project time
Ongoing — 30 daysEntra ID Authentication Control MigrationIT security team must inventory current Custom Controls for MFA and SSPR configurations and present a migration plan; executive sponsor may be needed to prioritize this work alongside other IT demand
Ongoing — 30 daysWindows 11 Version 26H2 ReadinessIT teams managing Windows endpoints should review readiness guidance now; no hard deadline yet, but early testing reduces deployment risk during annual update cycle

Sources: Exchange Team Blog · Microsoft Intune Blog · M365 Roadmap


If You Take No Action

Exchange Web Services retirement (October 2026): Business applications and integrations that have never been catalogued and migrated will stop delivering data when Microsoft disables EWS. The failure mode is silent until something breaks: automated reports stop arriving, ticketing integrations stop syncing, finance or HR workflows stop processing. Identifying these integrations requires internal audit time that cannot be compressed into the final weeks before the deadline. Organizations without a current inventory of API-based integrations should treat this as their most urgent IT project for the next 60 days.

Entra ID legacy authentication control retirement: Gaps in Conditional Access enforcement and inconsistent MFA application create specific, auditable vulnerabilities. Cyber insurers increasingly require evidence of consistent MFA enforcement across all authentication paths during policy renewal. Organizations still using Custom Controls for MFA that have not migrated to the supported replacement may face findings in their next SOC 2 audit or questions from their insurer. The risk compounds because attackers are actively using AI to accelerate credential-based intrusions, as Microsoft’s own threat intelligence confirms this week.

Office for Mac vulnerabilities unpatched: Any Mac running an unpatched version of Office for Mac is exposed to remote code execution, meaning an attacker can run arbitrary code on that machine by getting a user to open a crafted file. In environments where Macs are unmanaged or on a manual update cycle, this exposure may persist for weeks. The patch is available now.

Sources: Exchange Team Blog · Microsoft Entra Blog · Microsoft Security Response Center