Top 5

  1. GSA iOS Client, Cloud Firewall, and File-Type Filtering all hit GA — Three Global Secure Access capabilities landed in general availability simultaneously. The iOS client requires no new agent and runs through the existing MDE deployment. The cloud firewall enables 5-tuple filtering for branch office internet traffic via remote networks. File-type content filtering closes a meaningful gap for preventing data exfiltration through GenAI and SaaS apps. If you have been deferring SSE rollout on iOS or for remote network branches, the blockers are gone.

  2. Intune Data Warehouse beta connector v1 is retired — Any Power BI report built before November 2025 may still be pulling from the deprecated v1 connector. Those reports will break. Audit your Power BI workspace now and migrate to connector v2 or the OData Feed connector before the transition completes.

  3. Purview DLP policy sync drops from 2 hours to 30 minutes — Shipping in June CY2026, this change means policy changes propagate faster across the organization. No admin action is required, but it does close a window where users could exfiltrate data in the gap between policy update and enforcement.

  4. IRM can now create cases without content, with a new 2,000-case active limit — Insider Risk Management now allows case creation independent of content download, enabling higher-volume triage workflows. The new active case limit is 2,000; the content download limit remains 100. Review your IRM workflows if you have been hitting case ceiling constraints.

  5. Compromised @antv npm packages steal CI/CD credentials — The Mini Shai Hulud payload executes at npm install time and targets GitHub, AWS, Kubernetes, Vault, npm, and 1Password credentials on Linux CI/CD runners. Any pipeline using @antv packages should be treated as potentially compromised until audited.


Identity

  • Entitlement Management: Approver visibility GA in My Access [GA] — Requestors can now see approver names and email addresses for pending access package requests directly in the My Access portal. This reduces out-of-band email threads and speeds up access request resolution. The setting is enabled by default for members (non-guests) at the tenant level and can be scoped or disabled per access package in the Entra Admin Center.

  • Entra External ID Native Auth: Social Identity Providers GA via browser-delegated flows [GA] — Google, Facebook, and Apple sign-in are now generally available for Entra External ID applications using native authentication through web-view SDKs. Relevant if your organization builds customer-facing apps on Entra External ID and needs to support consumer identity providers alongside local accounts.

  • Windows 365 Government: External identity support GA [GA] — You can now provision Cloud PCs for external (guest) identities in Windows 365 Government tenants. Connection is supported via the latest Windows App on Windows. Review your licensing posture before provisioning, as external identity licensing rules apply.

  • Windows 365 Reserve: Additional client support for external identities in Preview [Preview] — External identity support has expanded to the Windows App on macOS and Android in preview. Check the platform comparison docs for current feature parity limitations before enabling this for external users on those clients.

  • Windows 365 Reserve: User-initiated provisioning in Public Preview [Preview] — Eligible users can now self-provision a Reserve Cloud PC from the Windows App when their primary device fails or is unavailable. The feature is off by default and scoped to Entra ID groups via Intune. Useful for business continuity planning, but confirm your licensing and group scope before enabling broadly.

  • Intune Connector for Active Directory: Updated low-privileged account build [GA] — A new build (6.2504.2001.8) has been published for the low-privileged Intune Connector for Active Directory, used in hybrid Autopilot scenarios. Download and install the latest version to pick up these fixes. Check your connector health in Intune after updating.


Devices

  • Intune: Userless ADE support for visionOS and tvOS [GA] — Intune now supports userless Apple automated device enrollment for Apple Vision Pro and Apple TV via Apple Business Manager or Apple School Manager. Apple access management settings in ABM/ASM can now control which services and apps are available on organization-owned devices. Useful for kiosk and shared-device deployments on these platforms.

  • Intune: Compliance report guidance for device-reported values [GA] — Updated documentation clarifies that the “Setting” column in compliance reports reflects values reported directly by the device and should be treated as informational only, not authoritative. This matters for custom compliance and Android app config reporting where device-reported data could be manipulated. Review how your team interprets these values in noncompliance investigations.

  • Intune: Compliance report documentation update for known reporting behaviors [GA] — New guidance covers expected discrepancies in compliance reporting related to check-in timing and user association. If your team has been raising tickets around seemingly incorrect compliance state in reports, review the updated “Known reporting behaviors” doc before escalating.

  • Intune: Remote Help connectivity improvement and new NotificationInfra.log [GA] — A new endpoint has been added to support Launch Remote Help connectivity from the Intune admin center. Update firewall rules to include the new endpoint. A new IME log file, NotificationInfra.log, now tracks notifications through the Microsoft real-time communication channel, which should help with Remote Help troubleshooting.

  • Intune Data Warehouse v1 (beta) connector retired [Preview] — The beta v1 Power BI connector for the Intune Data Warehouse is retired. Reports built before November 2025 may still reference it and will need migration to connector v2 or the OData Feed connector. Audit your Power BI workspace and update affected reports before the transition fully closes out.

  • Windows 365 Reserve: Autopilot Device Preparation in Public Preview [Preview] — Autopilot Device Preparation (DPP) is now available for Windows 365 Reserve. When linked to a Reserve provisioning policy in Intune, provisioning will wait until required apps and configurations are validated before completing. Cloud PCs will show “Preparing” status during setup. No changes to licensing or usage limits.

  • @antv npm package supply chain compromise: CI/CD credential theft [GA] — Compromised @antv packages drop the Mini Shai Hulud payload during npm install, targeting credentials stored for GitHub, AWS, Kubernetes, Vault, npm, and 1Password on Linux runners. Audit any pipeline or build environment that references @antv packages immediately and rotate potentially exposed secrets.


Apps

  • SharePoint: Microsoft 365 Archive file-level archiving in Preview [Preview] — File-level archiving for Microsoft 365 Archive is now in preview, with GA targeting June CY2026. This extends archiving granularity below the site level. If you are planning data lifecycle or storage cost management strategies around M365 Archive, start evaluating this capability now.

  • Teams: AI Interpreter Simultaneous mode enhancements [GA] — Three changes land in July CY2026: interpreter audio and live captions will match the user’s selected language, admins can fully disable voice simulation via policy, and dynamic voice assignments will distinguish speakers. If you have deployed AI Interpreter, review whether disabling voice simulation aligns with your organizational preferences and configure accordingly before GA.

  • Teams: Bookable desk experience with panel-based desk dock devices [GA] — The Teams panel app will support devices like the Yealink Linkhub for bookable desk experiences, showing availability and enabling walk-up booking. GA targets July CY2026. Each device requires a Teams Shared Space license; factor that into your flexible workspace licensing model.

  • Teams: Facilitator detects and answers unanswered meeting questions [GA] — Facilitator will now identify unanswered questions in meetings and offer to retrieve answers via web search, pending participant confirmation. GA targets July CY2026. If you have Facilitator governance policies in place, review whether web-search-grounded responses align with your acceptable use and information disclosure requirements.

  • Copilot: Project Manager Agent moving to GA in June CY2026 [Preview] — The Project Manager agent for M365 Copilot was in preview and GA is now expected in June. It covers core task and plan management. Note the roadmap update acknowledged the GA date slipped; keep an eye on the entry for final confirmation before communicating to end users.

  • Copilot: Mind Maps in Copilot Notebooks in Preview [Preview] — Mind Maps generate visual representations of notebook content across OneNote and the M365 Copilot App. Users can explore topic relationships and drill into nodes via Notebook chat. Available now in preview; no admin action required beyond standard Copilot licensing.

  • Copilot: Context IQ support for SharePoint Lists GA [GA] — Users can now search and select SharePoint Lists through the Context IQ menu to ground Copilot Chat prompts. This shipped in March CY2026 and is now broadly available. No admin action needed, but worth communicating to power users building Copilot workflows.

  • Copilot: Chat history filtering by Copilot experience [GA] — Chat history will now scope to the user’s current Copilot Chat endpoint by default, with an option to view all chats. GA targets June CY2026. This reduces cross-context confusion for users working across multiple Copilot entry points.

  • New Outlook: Navigate favorite folders without expanding the folder pane [Preview] — When the folder pane is collapsed, favorite folders will appear as a vertical list with unread/total counts. Preview targets August CY2026. No admin action required; relevant for organizations still managing the new Outlook rollout timeline.


Data

  • Purview IRM: Create cases without content, new 2,000 active case limit [GA] — Insider Risk Management now allows case creation without triggering content download. The active case limit increases to 2,000 (up from the previous lower threshold), while the active content download limit stays at 100. Content download can be initiated any time during an active case. Review your IRM case management workflows to take advantage of higher-volume triage at lower cost.

  • Purview DLP: Policy sync SLA drops from 2 hours to 30 minutes [GA] — DLP policy updates will propagate across the organization in 30 minutes instead of up to 2 hours. Shipping in June CY2026. No admin action required, but this reduces the enforcement gap window and should be noted in your change management processes for DLP policy updates.


Network

  • GSA iOS Client: General Availability [GA] — The Global Secure Access client on iOS and iPadOS is now generally available. No separate agent installation is needed: it leverages the existing MDE deployment to route traffic through Microsoft SSE for M365, internet access, and private access. If MDE is already deployed to iOS devices in your environment, enabling GSA is a low-friction next step.

  • GSA: Network content filtering based on file types GA [GA] — Global Secure Access now supports filtering file transfers by file type across GenAI and SaaS applications at the network level. This provides a control layer for preventing unauthorized data exfiltration that complements Purview DLP. Configure content policies in the Entra Admin Center under Internet Access.

  • GSA Cloud Firewall for Remote Networks: General Availability [GA] — Admins can now apply 5-tuple (source IP, destination IP, protocol, source port, destination port) filtering to all internet traffic from branch offices connected via GSA remote networks. This gives you consistent firewall policy enforcement for branch traffic without requiring on-premises appliances per site.

  • Windows 365: RDP Multipath with redundant TCP transport paths begins GA rollout [GA] — Windows 365 is rolling out RDP Multipath with redundant TCP transport paths. When network degradation is detected, the session automatically switches between TCP paths, complementing existing UDP-based multipath. The rollout is phased and quality-driven, so redundant TCP paths may not be active for all tenants immediately. No admin configuration required.


Visibility & Automation

  • Intune Change Review Agent: Risk recommendations in Multi Admin Approval [GA] — The Change Review Agent now surfaces risk-based recommendations directly in the Multi Admin Approval experience for PowerShell scripts. A new “Agent Response” column appears on the My Requests and All Requests tabs when a suggestion is available, and approvers can complete the workflow without leaving the node. This reduces context switching and gives approvers AI-assisted risk context at decision time.

  • RAMPART and Clarity: Open source agent safety tooling [GA] — Microsoft released two open source tools to address safety risks in agentic AI development. RAMPART and Clarity are designed to be integrated into agent development workflows to catch unsafe behaviors before deployment. If your organization is building or governing Copilot Studio agents or custom M365 agents, evaluate these tools as part of your agent security review process.

  • Fox Tempest: Malware-signing-as-a-service operation exposed [GA] — Microsoft has publicly attributed Fox Tempest as a financially motivated threat actor operating a malware-signing service used by groups including Vanilla Tempest and Storm clusters to distribute signed malware and ransomware. Review your signed binary trust policies and Defender for Endpoint allowlist configurations to ensure you are not inadvertently trusting Fox Tempest-signed payloads.

  • Multi-stage Linux intrusion via F5 BIG-IP and Confluence: Attack breakdown [GA] — A threat actor exploited an exposed F5 BIG-IP appliance to pivot to an internal Confluence server, then attempted Kerberos relay and lateral movement. Microsoft Defender detected and blocked the attack. This is a high-relevance read for any environment with externally exposed F5 or Confluence infrastructure. Ensure those assets are patched, access-restricted, and covered by Defender for Endpoint Linux sensors.

  • What’s new in Microsoft Security: May 2026 roundup [GA] — The monthly security update roundup covers expanded visibility and control across AI adoption scenarios. Worth a read for a consolidated view of May security feature releases across Defender, Purview, and Entra that may not all surface in individual product changelogs.


Action Required

  • Intune Data Warehouse v1 beta connector: Migrate Power BI reports now — The v1 connector is retired. Any Power BI report built before November 2025 may still reference the deprecated beta connector and will break when the transition completes. Inventory your Power BI workspace, identify reports using the old connector, and migrate them to connector v2 or the OData Feed connector. Do not wait for a hard deadline notice; the transition is actively in progress.

  • Intune Remote Help: Update firewall rules for new endpoint — A new network endpoint is required for the improved Launch Remote Help connectivity in the Intune admin center. Update your firewall allowlists to include the new endpoint listed in the Intune endpoints documentation under Remote Help. Without this change, Remote Help sessions initiated from the admin center may fail.

  • @antv npm supply chain compromise: Audit CI/CD pipelines and rotate secrets immediately — Any Linux-based CI/CD pipeline that has run npm install with @antv packages should be treated as potentially compromised. Audit pipeline logs for the Mini Shai Hulud payload execution, rotate all credentials accessible from those environments (GitHub tokens, AWS keys, Kubernetes service accounts, Vault tokens, npm tokens, 1Password service accounts), and remove or pin-to-known-good @antv package versions. Treat this as an active incident if the packages were used in the last 90 days.

  • GSA Cloud Firewall and file-type content filtering: Evaluate for deployment — Both capabilities are now GA with no blocking dependencies. If you have GSA remote networks deployed but have not configured cloud firewall policies, this is the week to build out your 5-tuple ruleset. Similarly, if exfiltration via GenAI or SaaS file uploads is in your threat model, the file-type content filtering policy in Internet Access should be prioritized in the next 30 days.

  • Purview DLP policy sync improvement: Update change management documentation — Shipping in June CY2026, the 30-minute sync SLA replaces the 2-hour window. If your runbooks or SOC playbooks reference the old 2-hour propagation time when assessing DLP policy change risk or scheduling maintenance windows, update those documents before the change takes effect.