Modern Work Weekly - Week of 2026-07-21
Passkeys become the default in Entra ID, Entra Backup and Recovery hits GA, and advanced Intune Suite capabilities land in M365 E3/E5 - a dense week for identity hardening and endpoint licensing.
A quick note before this week’s Top 5: publishing hit some backend hiccups over the past few weeks, so a few items below are catching up on real Microsoft 365 news from earlier this month rather than being brand new. That’s resolved now, the digest is back on its normal weekly cadence starting next week.
Top 5 This Week
Passkeys are now the default authentication method in Entra ID - Microsoft has shifted the default sign-in experience to passkeys and introduced a new model for SMS and voice authentication. Review your Conditional Access and authentication policies now; the default has moved whether you planned for it or not.
Microsoft Entra Backup and Recovery is generally available - Automatic daily backups of users, groups, apps, service principals, managed identities, and Conditional Access policies are rolling out to all workforce tenants with Entra ID P1 or P2. This directly addresses directory disaster recovery gaps that have historically required third-party tooling.
Advanced Intune Suite capabilities are now included in M365 E3 and E5 - As of July 1, the packaging changes announced in December 2025 are live. If your org holds M365 E5, you now have access to advanced Intune Suite features without an add-on; E3 gets a select subset. Audit your current Intune add-on licenses against what’s now included to avoid overspend.
Exchange 2016/2019 ESU ends October 2026, with no further extension - Microsoft has confirmed there will be no Period 3. If your organization is still running Exchange 2016 or 2019 on-premises, the migration deadline is real and the clock is running.
ACR Stealer campaigns actively targeting enterprise environments via ClickFix lures - Microsoft Defender Experts observed sustained ACR Stealer activity from late April through mid-June 2026, successfully harvesting browser credentials, auth tokens, and documents. Review your Defender for Endpoint coverage and user awareness posture around ClickFix-style social engineering.
Identity & Access
Defending SaaS-based applications against ShinyHunters OAuth abuse [GA] - If your org uses SaaS applications with OAuth integrations, ShinyHunters-affiliated tradecraft targeting misconfigured guest access and supply-chain compromise is an active threat to review. Microsoft Threat Intelligence documented vishing, supply-chain compromise, and guest access misconfigurations as the primary attack vectors. Audit your OAuth app consent grants, guest account access to SaaS apps, and CI/CD pipeline trust boundaries.
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID [GA] - Passkeys are now the default sign-in experience in Entra ID, and the model for SMS and voice authentication has changed. Read the full post to understand the new authentication method defaults and what you need to configure to prepare your users and helpdesk for the transition.
SharePoint Showcase: How Microsoft uses Copilot in SharePoint, and how you can get started [GA] - This monthly showcase recaps all newly GA SharePoint functionality and covers real Microsoft internal use cases for Copilot in SharePoint. Worth reviewing for a current-state inventory of what’s production-ready across the platform.
Windows 365 for Agents: A secured execution environment for AI agents [GA] - Organizations deploying AI agents in production now have a dedicated Cloud PC execution environment with consistent identity enforcement, policy application, and security visibility. Windows 365 for Agents addresses the fragmentation problem of agents running on local machines or unmanaged cloud infra. Evaluate this as your standard execution baseline if you’re moving agents from experimentation to production workloads.
Bring business logic into PIM role activation workflows [Preview] - Custom extensions for PIM are now in preview, letting you integrate external context (ticket validity, HR status, compliance checks, on-call schedules) directly into role activation workflows. If your privileged access model relies on out-of-band approvals or manual cross-checks, this significantly reduces that friction. Start testing integrations with your ITSM or HR systems now.
Microsoft Entra Backup and Recovery is now generally available [GA] - Daily automatic backups of users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, and more are now rolling out to all workforce tenants with Entra ID P1 or P2. This removes the primary justification for third-party Entra backup tooling for most organizations. Verify your tenant has received the rollout and validate the restore process before an incident forces you to discover gaps.
Endpoint & Device Management
Understanding Windows monthly updates: Servicing explained [Preview] - Microsoft published a structured guide covering monthly security updates, optional non-security preview updates, and the role of each in the servicing pipeline. Useful for onboarding new team members or aligning stakeholders on why preview updates exist and how to use them for pre-validation before Patch Tuesday releases land in production.
Windows news you can use: June 2026 [GA] - Windows 11 version 26H2 is now in the Insider Program for early validation, sharing the same servicing branch as 25H2 and 24H2, so devices update via enablement package with minimal disruption. The roundup also covers Build 2026 Windows 365 announcements including ready-to-code Cloud PCs and enterprise AI agent support. Start planning your 26H2 validation ring now if you haven’t already.
Advanced Microsoft Intune capabilities now available in Microsoft 365 E3 and E5 [GA] - As of July 1, the December 2025 packaging changes are live: advanced Intune Suite capabilities are included in M365 E5, with a select subset available in M365 E3. Capabilities address standing privilege reduction, certificate management modernization, and AI-assisted operations. Cross-reference your current Intune add-on subscriptions against the new inclusion list and remove redundant licenses to recapture budget.
Collaboration & Productivity
Cross-Tenant Message Recall in Exchange Online [GA] - Message Recall in Exchange Online now works across tenant boundaries, removing the single-tenant limitation that has been a consistent gap since the cloud-based recall feature launched in April 2023. This covers the scenario where a sensitive email is sent to an external recipient in another M365 tenant. No admin action is required to enable this, but update your incident response runbooks to reflect that recall is now a viable option for cross-org misdirected email.
Available today: OpenAI’s GPT-5.6 in Microsoft 365 Copilot [GA] - GPT-5.6 is now the preferred model powering Microsoft 365 Copilot across Word, Excel, PowerPoint, Chat, and Cowork, with stronger reasoning for agentic and multi-step work. This is a backend model swap; no user or admin action is needed, but set expectations with your user base that Copilot response quality and behavior may shift noticeably, particularly for complex multi-step tasks.
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud [GA] - Microsoft published detail on how the Secure Future Initiative uses AI-assisted continuous evaluation of live cloud services against security requirements. Relevant context for organizations building their own AI-assisted security operations posture and for understanding the direction Microsoft’s platform hardening is heading.
AI & Copilot
Native Dataverse Authorization (Public Preview) for Stronger Security in Power Pages [Preview] - Authorization for Power Pages external users is now enforced directly within Dataverse rather than at the portal layer, providing stronger security and improved visibility without changing the maker experience. If you’re running Power Pages with external user access, this is a meaningful security architecture improvement worth enabling in your dev/test environment now to evaluate before it reaches GA.
Dataverse Is Your Agent Data Platform: Here’s What’s New in July 2026 [GA] - July Dataverse updates expand the plugin to more coding agent marketplaces, extend MCP connectivity, introduce partner MCP certification for trusted adoption, and bring internal MCPs under enterprise governance. The MCP governance piece is the most operationally significant: if your org is running internal MCPs, review the new governance controls to ensure they’re scoped correctly before agents connect to them at scale.
Security & Compliance
CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row [GA] - Information published by MSRC. Review any environments running Perl DBI versions prior to 1.651 and apply updates; this affects database interaction integrity in Perl-based tooling, which may be present in legacy automation or pipeline scripts in your environment.
CVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done [GA] - Information published by MSRC. Slab-use-after-free in the Linux kernel TIPC subsystem during AEAD decryption. Assess exposure on Linux-based workloads and apply available kernel patches.
CVE-2026-63882 drm/amdkfd: fix NULL pointer bug in svm_range_set_attr [GA] - Information published by MSRC. Null pointer dereference in AMD kernel fusion driver for HSA. Relevant for environments running AMD GPU workloads on Linux; apply kernel updates as available.
CVE-2026-63879 drm/amdgpu: fix amdgpu_hmm_range_get_pages [GA] - Information published by MSRC. AMD GPU driver fix in the Linux kernel DRM subsystem. Patch Linux systems with AMD GPUs in your managed fleet.
CVE-2026-64077 netfilter: ebtables: move to two-stage removal scheme [GA] - Information published by MSRC. Linux kernel netfilter ebtables vulnerability. Relevant for any Linux systems using ebtables-based network filtering; prioritize patching on perimeter or container-host systems.
CVE-2026-63940 KVM: SEV: Ignore Port I/O requests of length ‘0’ [GA] - Information published by MSRC. KVM SEV (Secure Encrypted Virtualization) handling flaw. If you’re running AMD SEV-protected VMs in your infrastructure, apply available kernel patches.
CVE-2026-64097 drm/amd/display: Validate GPIO pin LUT table size before iterating [GA] - Information published by MSRC. AMD display driver bounds-checking fix in the Linux kernel. Apply kernel updates on AMD GPU-equipped Linux systems in your managed estate.
CVE-2026-64133 ALSA: asihpi: Fix potential OOB array access at reading cache [GA] - Information published by MSRC. Out-of-bounds array access in the ALSA asihpi audio driver. Scope is narrow but apply kernel patches where this hardware is present.
Secure AI, web, and private apps with Zero Trust [Preview] - Microsoft Entra Internet Access and Entra Private Access now extend Zero Trust policy enforcement to AI agent traffic, not just users and devices. This is a material capability expansion for organizations where agents are initiating network requests across enterprise resources. Evaluate how your current Global Secure Access deployment handles agent-originated traffic and whether new policies are needed.
Reminder: Exchange 2016 and 2019 ESU Program Ends in October 2026 [GA] - Microsoft has confirmed there will be no Period 3 ESU extension for Exchange 2016/2019. After October 2026, no further security updates will be issued regardless of what you’re paying for. If you have on-premises Exchange 2016 or 2019 in your environment, escalate the migration timeline immediately.
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks [GA] - Microsoft Security is presenting supply chain research and hands-on security experiences at Black Hat USA 2026. Relevant for teams tracking supply chain threat intelligence; the research previewed here ties directly to the AsyncAPI npm compromise covered separately this week.
ACR Stealer: Two observed intrusion chains amid increased threat activity [GA] - ACR Stealer campaigns were active from late April through mid-June 2026 using ClickFix lures to steal browser credentials, auth tokens, and sensitive documents. Microsoft Defender Experts documented two distinct intrusion chains. Review your Defender for Endpoint detections for ClickFix-related indicators and ensure users are trained to recognize social engineering that prompts manual script execution.
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery [GA] - Threat actors compromised AsyncAPI npm packages and weaponized CI/CD workflows to deliver import-time malware payloads. If your pipelines consume AsyncAPI packages, audit your dependency chain and verify package integrity. More broadly, review your npm dependency governance and whether import-time execution risks are mitigated in your build environments.
Action Required
Exchange 2016/2019 ESU ends October 2026, no extension - deadline: October 2026 [GA] - Deadline: end of October 2026, confirmed final. Microsoft has explicitly ruled out any further extension. Organizations still running Exchange 2016 or 2019 on-premises need an active migration project in flight now; three months is not enough time to start from scratch if you haven’t already begun.
Passkeys are now the default in Entra ID - review authentication policies immediately [GA] - This change is live. Audit your Authentication Methods policies, update user communications, and brief your helpdesk on the new SMS/voice authentication model. Users who haven’t registered a passkey may encounter a different sign-in flow than expected.
Entra Backup and Recovery is GA - validate your restore process now [GA] - Rolling out this week to all workforce tenants with Entra ID P1/P2. Confirm your tenant has received the feature, review what objects are covered, and run a test restore before you need it in an actual incident. If you’re paying for a third-party Entra backup solution, re-evaluate whether it’s still necessary given the native coverage.
Advanced Intune Suite now in M365 E3/E5 - audit add-on licenses for overspend [GA] - Effective July 1. If your org has standalone Intune Suite add-on licenses that are now covered by M365 E3 or E5 entitlements, you may be paying for redundant licenses. Review the inclusion table in the post and coordinate with your licensing team to remove unnecessary add-ons at the next renewal or true-up.
ACR Stealer / ClickFix campaigns actively targeting enterprise environments [GA] - Ongoing threat. Pull Defender for Endpoint detections for ClickFix-related indicators from the documented intrusion chains. Verify that browser credential isolation and token protection controls are enabled. Escalate user awareness training if ClickFix-style lures (prompts to copy/paste PowerShell or run scripts) are not covered in your current security awareness program.
Sources
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/understanding-windows-monthly-updates-servicing-explained/ba-p/4532290
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-june-2026/ba-p/4532288
- https://techcommunity.microsoft.com/t5/microsoft-intune-blog/advanced-microsoft-intune-capabilities-now-available-in/ba-p/4529335
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-60082
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63801
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63882
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63879
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64077
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63940
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64097
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64133
- https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-ai-web-and-private-apps-with-zero-trust/ba-p/4516387
- https://techcommunity.microsoft.com/t5/exchange-team-blog/reminder-exchange-2016-and-2019-esu-program-ends-in-october-2026/ba-p/4539033
- https://www.microsoft.com/en-us/security/blog/2026/07/17/microsoft-at-black-hat-usa-2026-defending-trust-in-the-age-of-ai-and-supply-chain-attacks/
- https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/
- https://www.microsoft.com/en-us/security/blog/2026/07/15/unpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery/
- https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/
- https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/sharepoint-showcase-how-microsoft-uses-copilot-in-sharepoint-and/ba-p/4533156
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-365-for-agents-a-secured-execution-environment-for-ai/ba-p/4529336
- https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bring-business-logic-into-pim-role-activation-workflows/ba-p/4531380
- https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-backup-and-recovery-is-now-generally-available/ba-p/4521997
- https://techcommunity.microsoft.com/t5/exchange-team-blog/cross-tenant-message-recall-in-exchange-online/ba-p/4535800
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/available-today-openai-s-gpt-5-6-in-microsoft-365-copilot/ba-p/4533152
- https://www.microsoft.com/en-us/security/blog/2026/07/08/protecting-microsoft-at-ai-speed-how-sfi-proactively-hardens-our-cloud/
- https://www.microsoft.com/en-us/power-platform/blog/power-pages/native-dataverse-authorization-public-preview-for-stronger-security-in-power-pages/
- https://www.microsoft.com/en-us/power-platform/blog/2026/07/06/dataverse-july2026/
