Top 5

  1. EWS retirement final phase, October 2026 deadline. Exchange Web Services disablement in Exchange Online is now approaching. Microsoft has introduced EWSAllowedAppIDs as a controlled allow-list bridge, but the clock is ticking. Any workload still on EWS that is not cataloged and either migrated or explicitly allow-listed will break in October. Start your audit now.

  2. Entra ID retiring Custom Controls, unenforced CA during registration, and unregistered SSPR methods. Three legacy identity gaps are closing simultaneously. Custom Controls are being replaced by External MFA, Conditional Access will be enforced consistently during credential registration, and SSPR will require explicitly registered methods. Existing configs continue during transition, but migration planning is overdue for most tenants.

  3. Intune Suite advanced capabilities arrive in M365 E3/E5 by August 1. Packaging changes are effective July 1; eligible tenants receive capabilities by August 1. If you are not already scoping which Intune Suite features apply to your environment, do it before the rollout lands so you can configure and communicate the changes deliberately rather than reactively.

  4. AutoJack: AI browsing agents can be turned into RCE vectors via a single malicious webpage. The exploit chain abuses localhost trust, missing authentication, and unsafe parameter handling in AutoGen Studio’s MCP WebSocket. If your organization is piloting or running AI agents that browse untrusted content, this research is required reading for your security architecture review.

  5. Windows 11 version 26H2 preparation guide is live. The next annual Windows 11 update is in Insider channels now. Microsoft is positioning it as a low-disruption update for devices already on recent 11 releases. Start your compatibility testing cycle and review your Autopatch or WSUS ring configurations before GA hits production.


Identity

  • Microsoft Entra ID security updates: What organizations need to do now [GA] — Three retirement tracks are running in parallel: Custom Controls replaced by External MFA, Conditional Access enforcement gaps during credential registration are closing, and SSPR is being locked to explicitly registered methods. Existing configurations remain functional during the transition window, but you should map your current CA policies and any Custom Control dependencies now and build a migration timeline. Tenants that treat this as low priority will face broken auth flows when enforcement dates arrive.

  • AI is accelerating cyberattacks — here’s how to stay ahead [GA] — Microsoft’s latest identity security posture guidance emphasizes that AI is compressing attacker timelines across the full kill chain: automated credential analysis, scaled social engineering, and real-time tactic adaptation. The practical recommendation is to unify identity and security signals in Defender XDR and ensure your Conditional Access policies cover all authentication paths, not just interactive login. Review your named locations, device compliance requirements, and sign-in risk policies against this threat model.

  • AutoJack: How a single page can RCE the host running your AI agent [GA] — A malicious webpage can weaponize an AI browsing agent running AutoGen Studio against the host machine by exploiting unauthenticated MCP WebSocket access and unsafe parameter handling. Localhost is no longer a trust boundary when agents are browsing untrusted content. If any AI agent workloads in your environment have web browsing capability and local service access, enforce network segmentation, require WebSocket authentication, and audit what local interfaces agents can reach.


Devices

  • IT experts weigh in: Advanced Intune capabilities coming to Microsoft 365 E3 and E5 [GA] — Advanced Intune Suite capabilities become part of M365 E3 and E5 effective July 1, with eligible tenants receiving them in-tenant by August 1. This includes capabilities like Remote Help, Endpoint Privilege Management, and Advanced Analytics that previously required a separate Intune Suite add-on license. Review the MVP-curated guides in the linked post to scope which capabilities apply to your fleet, and plan user communications and policy configuration before the rollout hits automatically.

  • Get ready for Windows 11, version 26H2 [GA] — Windows 11 26H2 is in Insider channels now, with the annual update positioned as low-disruption for devices already on recent 11 versions. For devices still on Windows 10 or older 11 releases, the delta is larger. Start application compatibility testing, review your Autopatch or Windows Update for Business ring definitions, and verify your support readiness timeline before GA release.


Apps

  • Introducing EWSAllowedAppIDs: Preparing for the Final Phase of EWS Retirement [GA] — EWS disablement in Exchange Online arrives in October 2026, and Microsoft has introduced EWSAllowedAppIDs as a controlled allow-list to give administrators a predictable path through the cutover. Use this now to enumerate which app IDs are still calling EWS in your tenant, then prioritize migration to Microsoft Graph for each one. Any app not migrated and not on the allow-list will stop working at disablement. This is not a soft deadline.

  • Copilot Cowork is now GA [GA] — Copilot Cowork, the agentic multi-step task execution system, is now generally available worldwide. The M365 Copilot app has been redesigned with a toggle between everyday chat and Cowork, and a new home page surfaces tasks in progress. For organizations managing Copilot rollout, this is a meaningful capability expansion: Cowork operates with greater autonomy than standard Copilot chat, so review your data access policies and sensitivity label coverage before broad enablement.

  • A new SharePoint Look and Feel: What’s Changing and Why It Matters [GA] — SharePoint’s visual refresh is rolling out, targeting reduced visual noise, improved readability, and a more consistent interface. Microsoft states that existing organizational branding investments are preserved. Validate that custom themes, site designs, and any injected header/footer customizations render correctly in the new experience, and flag any branded intranet sites for testing before the rollout reaches your tenant.

  • Microsoft Teams: Block all identified external bots automatically from joining your meetings [GA] — Teams will add an admin control to automatically block all identified external AI bots from joining meetings, extending existing bot governance capabilities. GA is targeted for August 2026. If your organization has meeting security policies or compliance requirements around external participants, start drafting the policy configuration and user guidance now so you can enable this on day one.

  • CVE-2026-45469 Microsoft Excel Remote Code Execution Vulnerability [GA] — RCE vulnerability in Microsoft Office for Mac. Security updates are available now. Mac users running affected Office software must install the update; no action is required for Windows Office users. Verify your Mac software update policies in Intune or your MDM of choice and confirm the patch has been applied across your Mac fleet.

  • CVE-2026-45475 Microsoft Office Remote Code Execution Vulnerability [GA] — A second RCE vulnerability in Microsoft Office for Mac, addressed in the same update cycle as CVE-2026-45469. Apply the Mac Office security update via your MDM patching workflow and verify compliance reporting shows full coverage before end of week.

  • CVE-2025-4574 Crossbeam-channel: double free on drop vulnerability [GA] — Memory safety vulnerability in the crossbeam-channel Rust crate. Relevant if your organization develops or deploys software that uses this dependency. Review your internal software supply chain for crossbeam-channel usage and update affected packages.


Data

No new items this week.


Network

No new items this week.


Visibility & Automation

  • Microsoft Signing Transparency (MST) now GA [GA] — Microsoft is now recording production software builds for critical cloud services into a publicly verifiable SCITT-compliant blockchain ledger, starting with Azure Attestation, Azure Managed HSM, and Azure confidential ledger. This gives security teams an external, tamper-evident reference for verifying the integrity of Microsoft cloud service builds. Incorporate MST verification into your supply chain security reviews and vendor assessment processes.

  • Guarding AI memory [GA] — Microsoft Security Blog breaks down attacker techniques targeting AI memory and persistent context stores, including prompt injection through memory and cross-session data leakage. For organizations running Copilot or custom AI agents with memory features enabled, review what data those memory stores can access and whether your DLP and information protection policies extend to AI-generated memory artifacts.

  • One intrusion, two cyberattackers: Uncovering parallel threat activity [GA] — A ransomware case analysis showing two parallel threat actors operating within the same compromised environment simultaneously, blending TTPs and evasion techniques in ways that defeat alert-by-alert triage. The key takeaway for defenders: isolated signals in your SIEM will miss overlapping intrusions. Review your Defender XDR incident correlation rules and ensure your SOC workflow correlates across identity, endpoint, and network signals before closing incidents.

  • CVE-2026-44967 opentelemetry-cpp: unbounded HTTP response read [GA] — Vulnerability in OTLP HTTP exporters in opentelemetry-cpp. Relevant for teams running observability pipelines or custom telemetry exporters built on this library. Audit your observability tooling for this dependency and apply available patches.

  • CVE-2026-46331 net/sched: pedit partial COW page cache corruption [GA] — Linux kernel networking scheduler vulnerability affecting page cache integrity. Relevant for Linux-based infrastructure in your M365 adjacent environment, including any Linux VMs, containers, or edge nodes. Ensure your Linux patching pipeline has picked this up.

  • CVE-2026-34180 and CVE-2026-7383: ASN.1 heap buffer vulnerabilities [GA] — Two memory safety vulnerabilities in ASN.1 parsing, one a heap buffer over-read in content parsing and one a possible heap buffer overflow in multibyte string conversion. ASN.1 is foundational to certificate and cryptographic processing. Review whether any internal tooling or services use affected libraries and apply patches promptly.


Action Required

  • EWS disablement in Exchange Online — October 2026 deadline [GA] — Deadline: October 2026. Use the newly available EWSAllowedAppIDs allow-list feature immediately to audit which applications in your tenant are still calling EWS. Build a migration-to-Graph plan for each identified workload. Any unmigrated and unallowed application stops functioning at disablement. Do not treat this as a future problem.

  • Entra ID: Migrate off Custom Controls, fix CA registration gaps, enforce SSPR method registration [GA] — No single published cutoff date, but enforcement is coming. Map every Conditional Access policy that uses Custom Controls and begin the transition to External MFA. Audit CA policies for registration enforcement gaps and verify SSPR is restricted to explicitly registered methods. Existing configurations continue during the transition, but the window to migrate cleanly is open now.

  • Intune Suite advanced capabilities in M365 E3/E5 — effective July 1, in-tenant by August 1 [GA] — Deadline: August 1, 2026. Packaging change is effective July 1. Identify which Intune Suite capabilities are newly included for your license tier, plan configuration for features like Endpoint Privilege Management and Remote Help, and prepare user and helpdesk communications before capabilities land automatically in tenant.

  • CVE-2026-45469 and CVE-2026-45475: Office for Mac RCE patches [GA] — Immediate action required for Mac fleets. Apply the Microsoft Office for Mac security update via your MDM patching workflow now. Verify compliance reporting shows full coverage across all managed Mac devices before end of this week.

  • AI agent security review: AutoJack RCE exploit chain [GA] — Urgent architecture review recommended for any environment running AI agents with web browsing capability and local service access. Enforce network segmentation between agent processes and local interfaces, require WebSocket authentication for MCP endpoints, and restrict what local services are accessible from agent execution contexts.