Modern Work Weekly — Week of 2026-06-09
Teams Live Events dies June 30 — migrate now. Exchange Server OWA has an active XSS CVE. Meanwhile, Purview ships posture reporting, Copilot Studio goes fully agentic with computer-use GA, and Entra tackles shadow tenant sprawl.
Top 5 This Week
CVE-2026-42897 — Exchange Server OWA XSS (Active Vulnerability): All on-prem Exchange 2016, 2019, and SE versions are affected by an XSS flaw exploitable via a crafted email opened in OWA. Exchange Online is unaffected. Patch or mitigate immediately — no excuse to wait on this one.
Teams Live Events retirement — June 30, 2026: Scheduling closes in three weeks. Any live events already on the calendar will run through February 28, 2027, but nothing new can be created after the deadline. If you have recurring large-format event workflows or Graph API integrations built on live events, migration to Town Hall is urgent, not optional.
Computer-Using Agents in Copilot Studio now GA: Agents can now drive UI in vendor portals, legacy line-of-business apps, and internal web tools without APIs or brittle RPA scripts. This materially expands the automation surface — and the governance surface. Review your Copilot Studio data loss prevention and connector policies before agents start clicking through apps that hold sensitive data.
Entra Tenant Governance — Shadow Tenant Discovery GA: If your org has grown through acquisitions, dev projects, or regional expansion, there are almost certainly tenants outside your visibility. This feature surfaces them via B2B, multitenant app, and billing signals. Run discovery before your next security review.
Purview Data Security Posture Reports GA + Custom Workspaces in Preview: You can now produce executive-ready evidence that sensitivity labels and DLP policies are actually reducing risk at scale — not just that policies exist. The custom workspace/charts feature is in preview. Both are worth enabling now if you’re heading into an audit cycle.
Identity
Adaptive Context-Based Redirections in Windows 365 — Public Preview [Preview] — Windows App now supports granular device and resource redirection controls driven by compliance posture, device management state, group membership, and network conditions. This is the BYOD story for Cloud PCs: users on unmanaged or contractor-managed devices get contextually scoped access rather than blanket block-or-allow. Evaluate for your unmanaged device population.
Reducing NTLM Dependency: IAKerb and LocalKDC in Windows Insider Preview [Preview] — IAKerb and LocalKDC extend Kerberos to workgroup and local authentication scenarios that have historically required NTLM fallback. Currently Canary Channel only, but this is the foundational work for eventually blocking NTLM at the OS level. Start tracking this if NTLM deprecation is on your roadmap.
Apps
Copilot in OneNote Now Understands Images, Tables, and Note Tags [GA] — Copilot’s grounding in OneNote now extends beyond typed text to include images, tables, and note tags, improving accuracy of summarization and extraction across rich-content notebooks. No admin action required, but worth communicating to users whose notebooks rely heavily on structured or visual content.
Microsoft 365 Copilot Achieves ISO 42001 Recertification [GA] — Copilot and Copilot Chat completed their second consecutive ISO/IEC 42001:2023 recertification with zero non-conformities. If you’re managing AI risk registers or responding to procurement questionnaires about AI system governance, this certification evidence is now available for year two.
Finance Agent in Microsoft 365 Copilot — Expanded Capabilities [GA] — The Finance Agent now covers a broader range of finance workflows including record-to-report, source-to-pay, and forecast-to-plan scenarios. If your finance team is on M365 Copilot, this is worth a pilot — but ensure your data residency and sensitivity label coverage over financial data is solid before broad rollout.
Copilot in PowerPoint Agent Mode — Style Reference from Existing Deck [Preview] — Delayed in development; rolling out mid-June 2026. When available, Copilot Agent Mode in PowerPoint will apply an attached deck’s theme and styles to newly generated presentations, reducing manual reformatting. Watch for Message Center confirmation before communicating GA to users.
Data
AI-Powered DLM Diagnostics MCP Server — Open Source Release [GA] — Microsoft has open-sourced a Model Context Protocol (MCP) server that enables AI-driven diagnosis of Data Lifecycle Management policy failures — retention not applying, archive mailboxes not expanding, inactive mailbox purge failures. This is a practical operational tool; worth deploying if your team regularly debugs DLM policy behavior.
Microsoft Purview Referential Architecture Diagrams [GA] — Updated reference architecture diagrams covering classification, sensitivity labeling, DLP, and Insider Risk signal flows across M365 workloads. Use these for design reviews, onboarding documentation, and communicating policy enforcement boundaries to stakeholders — they’re the clearest official representation of how Purview evaluation actually works.
Building a Curated Agent Store to Scale Agent Adoption [GA] — Guidance on creating governed, curated agent catalogs that prevent ungoverned agent sprawl while enabling business adoption. Directly relevant to orgs trying to balance “let teams build agents” with “don’t let agents exfiltrate data or accumulate permissions.”
Network
- The Gentlemen Ransomware — Storm-2697 Go-Based Self-Propagating Encryptor [GA] — Microsoft Threat Intelligence analysis of a Go-based ransomware using per-file ephemeral key encryption combined with simultaneous lateral movement techniques across target networks. Review the IOCs and lateral movement TTPs against your network segmentation and Defender for Endpoint detection rules — self-propagation at this level makes containment time-critical.
Visibility & Automation
Computer-Using Agents in Copilot Studio — Now GA [GA] — Agents can now directly interact with browser UIs, vendor portals, and legacy line-of-business systems without APIs or RPA tooling. This is a significant expansion of the automation attack surface: review your DLP, connector governance, and Conditional Access policies for Copilot Studio before agents start operating against sensitive internal systems.
Agent Evaluation in Copilot Studio — Now GA [GA] — Automated evaluation runs test sets against agents at scale to validate behavior, tool usage, and response correctness continuously — not just at build time. For production agents handling sensitive workflows, this is table stakes: configure evaluation pipelines before agents go live, not after incidents.
Automate Agent Evaluation with Evaluation APIs [GA] — The Evaluation APIs extend the GA Agent Evaluation capability to CI/CD pipelines, enabling automated regression testing as agents evolve. If your dev team is shipping agent updates on a cadence, integrate these APIs into your deployment gates now.
Microsoft Edge Security Update Alerts in Edge Management Service [Preview] — Admins will be able to set a severity threshold and receive alerts when an Edge update contains security fixes at or above that level, including zero-days. GA targeted July 2026; preview available now. Enroll if you need tighter control over security-driven Edge update urgency communication.
Windows 365 at Build 2026 — Developer and Agent Workload Expansions [GA] — Build 2026 announcements position Windows 365 as compute infrastructure for both developers (streamlined onboarding, flexible SKUs) and autonomous agents (secure, governed execution environments). If your org is planning agent infrastructure at scale, Windows 365 is now a first-class option alongside Azure Container Instances.
Action Required
CVE-2026-42897 — Exchange Server OWA XSS — PATCH NOW [GA] — Immediate action required. All on-premises Exchange 2016, 2019, and SE installations are vulnerable to JavaScript injection via crafted email in OWA. Exchange Online is not affected. Apply the May 2026 security update to all on-prem Exchange servers now — the exploit requires only that a user open a malicious email in OWA, making this a low-barrier, high-impact risk.
Teams Live Events Retirement — Deadline June 30, 2026 [GA] — 21 days remaining. New live event scheduling closes permanently on June 30, 2026. Audit all scheduled live events, identify Graph API integrations that create or manage live events, and migrate event workflows to Town Hall before the deadline. Events already scheduled will run until February 28, 2027.
Exchange 2016/2019 ESU Period 2 Enrollment [GA] — Active now through October 2026. If you’re still running Exchange 2016 or 2019 and Period 1 ESU has lapsed, enroll in Period 2 immediately — both to receive security patches (including CVE-2026-42897 mitigations) and to maintain a supported posture while completing migration to Exchange SE. Running unpatched on these versions is now a critical risk.
Computer-Using Agents in Copilot Studio — Governance Review Required [GA] — Review within 30 days. With computer-use agents now GA, agents can interact with any web UI including internal systems holding sensitive data. Audit your Copilot Studio environment, Conditional Access policies, and DLP rules before agents are deployed against production systems. Establish agent identity governance policies aligned to the Entra guidance published this week.
Intune Suite Capabilities Rolling Into Microsoft 365 — CY26 Q3 [GA] — Plan within 30 days. Advanced Intune Suite features will begin appearing in M365 tenants in CY26 Q3 with 30-day Message Center notice. Review your current Intune Suite add-on licensing — if you’re paying for standalone Suite SKUs that will be included in your M365 plan, you’ll want to adjust renewal planning before overspending on the next cycle.
Sources
- https://techcommunity.microsoft.com/t5/microsoft-intune-blog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/ba-p/4474272
- https://techcommunity.microsoft.com/t5/copilot-studio-blog/automate-agent-evaluation-with-the-evaluation-apis/ba-p/4511653
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/copilot-in-onenote-now-understands-more-of-your-notes/ba-p/4515922
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/recertified-how-microsoft-365-copilot-continues-to-earn-trust/ba-p/4521693
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/scaling-the-reach-of-finance-what-s-next-with-finance-agent-in/ba-p/4522976
- https://techcommunity.microsoft.com/t5/exchange-team-blog/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/ba-p/4518498
- https://www.microsoft.com/microsoft-365/roadmap?id=555880
- https://www.microsoft.com/microsoft-365/roadmap?id=558435
- https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-period-2-exchange-2016-2019-extended-security-update/ba-p/4511603
- https://techcommunity.microsoft.com/t5/copilot-studio-blog/computer-using-agents-in-microsoft-copilot-studio-are-now/ba-p/4519427
- https://techcommunity.microsoft.com/t5/copilot-studio-blog/agent-evaluation-in-microsoft-copilot-studio-is-now-generally/ba-p/4507392
- https://techcommunity.microsoft.com/t5/microsoft-teams-blog/retiring-teams-live-events-the-next-chapter-for-events-at-scale/ba-p/4486465
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/made-for-developers-and-agents-windows-365-at-build-2026/ba-p/4519041
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/adaptive-data-protection-with-context-based-redirections-in/ba-p/4521366
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/reducing-ntlm-dependency-iakerb-and-localkdc-in-windows-insider/ba-p/4524615
- https://techcommunity.microsoft.com/t5/copilot-studio-blog/4-ways-to-build-a-curated-agent-store-and-scale-agent-adoption/ba-p/4518575
- https://techcommunity.microsoft.com/t5/microsoft-purview-blog/ai-powered-troubleshooting-for-microsoft-purview-data-lifecycle/ba-p/4502660
- https://techcommunity.microsoft.com/t5/microsoft-purview-blog/microsoft-purview-referential-architecture-diagrams/ba-p/4510925
- https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/
