A quick note before this week’s Top 5: publishing hit some backend hiccups over the past few weeks, so a few items below are catching up on real Microsoft 365 news from earlier this month rather than being brand new. That’s resolved now, the digest is back on its normal weekly cadence starting next week.

Top 5 This Week

  1. Passkeys are now the default authentication method in Entra ID - Microsoft has shifted the default sign-in experience to passkeys and introduced a new model for SMS and voice authentication. Review your Conditional Access and authentication policies now; the default has moved whether you planned for it or not.

  2. Microsoft Entra Backup and Recovery is generally available - Automatic daily backups of users, groups, apps, service principals, managed identities, and Conditional Access policies are rolling out to all workforce tenants with Entra ID P1 or P2. This directly addresses directory disaster recovery gaps that have historically required third-party tooling.

  3. Advanced Intune Suite capabilities are now included in M365 E3 and E5 - As of July 1, the packaging changes announced in December 2025 are live. If your org holds M365 E5, you now have access to advanced Intune Suite features without an add-on; E3 gets a select subset. Audit your current Intune add-on licenses against what’s now included to avoid overspend.

  4. Exchange 2016/2019 ESU ends October 2026, with no further extension - Microsoft has confirmed there will be no Period 3. If your organization is still running Exchange 2016 or 2019 on-premises, the migration deadline is real and the clock is running.

  5. ACR Stealer campaigns actively targeting enterprise environments via ClickFix lures - Microsoft Defender Experts observed sustained ACR Stealer activity from late April through mid-June 2026, successfully harvesting browser credentials, auth tokens, and documents. Review your Defender for Endpoint coverage and user awareness posture around ClickFix-style social engineering.


Identity & Access

  • Defending SaaS-based applications against ShinyHunters OAuth abuse [GA] - If your org uses SaaS applications with OAuth integrations, ShinyHunters-affiliated tradecraft targeting misconfigured guest access and supply-chain compromise is an active threat to review. Microsoft Threat Intelligence documented vishing, supply-chain compromise, and guest access misconfigurations as the primary attack vectors. Audit your OAuth app consent grants, guest account access to SaaS apps, and CI/CD pipeline trust boundaries.

  • Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID [GA] - Passkeys are now the default sign-in experience in Entra ID, and the model for SMS and voice authentication has changed. Read the full post to understand the new authentication method defaults and what you need to configure to prepare your users and helpdesk for the transition.

  • SharePoint Showcase: How Microsoft uses Copilot in SharePoint, and how you can get started [GA] - This monthly showcase recaps all newly GA SharePoint functionality and covers real Microsoft internal use cases for Copilot in SharePoint. Worth reviewing for a current-state inventory of what’s production-ready across the platform.

  • Windows 365 for Agents: A secured execution environment for AI agents [GA] - Organizations deploying AI agents in production now have a dedicated Cloud PC execution environment with consistent identity enforcement, policy application, and security visibility. Windows 365 for Agents addresses the fragmentation problem of agents running on local machines or unmanaged cloud infra. Evaluate this as your standard execution baseline if you’re moving agents from experimentation to production workloads.

  • Bring business logic into PIM role activation workflows [Preview] - Custom extensions for PIM are now in preview, letting you integrate external context (ticket validity, HR status, compliance checks, on-call schedules) directly into role activation workflows. If your privileged access model relies on out-of-band approvals or manual cross-checks, this significantly reduces that friction. Start testing integrations with your ITSM or HR systems now.

  • Microsoft Entra Backup and Recovery is now generally available [GA] - Daily automatic backups of users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, and more are now rolling out to all workforce tenants with Entra ID P1 or P2. This removes the primary justification for third-party Entra backup tooling for most organizations. Verify your tenant has received the rollout and validate the restore process before an incident forces you to discover gaps.


Endpoint & Device Management

  • Understanding Windows monthly updates: Servicing explained [Preview] - Microsoft published a structured guide covering monthly security updates, optional non-security preview updates, and the role of each in the servicing pipeline. Useful for onboarding new team members or aligning stakeholders on why preview updates exist and how to use them for pre-validation before Patch Tuesday releases land in production.

  • Windows news you can use: June 2026 [GA] - Windows 11 version 26H2 is now in the Insider Program for early validation, sharing the same servicing branch as 25H2 and 24H2, so devices update via enablement package with minimal disruption. The roundup also covers Build 2026 Windows 365 announcements including ready-to-code Cloud PCs and enterprise AI agent support. Start planning your 26H2 validation ring now if you haven’t already.

  • Advanced Microsoft Intune capabilities now available in Microsoft 365 E3 and E5 [GA] - As of July 1, the December 2025 packaging changes are live: advanced Intune Suite capabilities are included in M365 E5, with a select subset available in M365 E3. Capabilities address standing privilege reduction, certificate management modernization, and AI-assisted operations. Cross-reference your current Intune add-on subscriptions against the new inclusion list and remove redundant licenses to recapture budget.


Collaboration & Productivity

  • Cross-Tenant Message Recall in Exchange Online [GA] - Message Recall in Exchange Online now works across tenant boundaries, removing the single-tenant limitation that has been a consistent gap since the cloud-based recall feature launched in April 2023. This covers the scenario where a sensitive email is sent to an external recipient in another M365 tenant. No admin action is required to enable this, but update your incident response runbooks to reflect that recall is now a viable option for cross-org misdirected email.

  • Available today: OpenAI’s GPT-5.6 in Microsoft 365 Copilot [GA] - GPT-5.6 is now the preferred model powering Microsoft 365 Copilot across Word, Excel, PowerPoint, Chat, and Cowork, with stronger reasoning for agentic and multi-step work. This is a backend model swap; no user or admin action is needed, but set expectations with your user base that Copilot response quality and behavior may shift noticeably, particularly for complex multi-step tasks.

  • Protecting Microsoft at AI speed: How SFI proactively hardens our cloud [GA] - Microsoft published detail on how the Secure Future Initiative uses AI-assisted continuous evaluation of live cloud services against security requirements. Relevant context for organizations building their own AI-assisted security operations posture and for understanding the direction Microsoft’s platform hardening is heading.


AI & Copilot

  • Native Dataverse Authorization (Public Preview) for Stronger Security in Power Pages [Preview] - Authorization for Power Pages external users is now enforced directly within Dataverse rather than at the portal layer, providing stronger security and improved visibility without changing the maker experience. If you’re running Power Pages with external user access, this is a meaningful security architecture improvement worth enabling in your dev/test environment now to evaluate before it reaches GA.

  • Dataverse Is Your Agent Data Platform: Here’s What’s New in July 2026 [GA] - July Dataverse updates expand the plugin to more coding agent marketplaces, extend MCP connectivity, introduce partner MCP certification for trusted adoption, and bring internal MCPs under enterprise governance. The MCP governance piece is the most operationally significant: if your org is running internal MCPs, review the new governance controls to ensure they’re scoped correctly before agents connect to them at scale.


Security & Compliance


Action Required

  • Exchange 2016/2019 ESU ends October 2026, no extension - deadline: October 2026 [GA] - Deadline: end of October 2026, confirmed final. Microsoft has explicitly ruled out any further extension. Organizations still running Exchange 2016 or 2019 on-premises need an active migration project in flight now; three months is not enough time to start from scratch if you haven’t already begun.

  • Passkeys are now the default in Entra ID - review authentication policies immediately [GA] - This change is live. Audit your Authentication Methods policies, update user communications, and brief your helpdesk on the new SMS/voice authentication model. Users who haven’t registered a passkey may encounter a different sign-in flow than expected.

  • Entra Backup and Recovery is GA - validate your restore process now [GA] - Rolling out this week to all workforce tenants with Entra ID P1/P2. Confirm your tenant has received the feature, review what objects are covered, and run a test restore before you need it in an actual incident. If you’re paying for a third-party Entra backup solution, re-evaluate whether it’s still necessary given the native coverage.

  • Advanced Intune Suite now in M365 E3/E5 - audit add-on licenses for overspend [GA] - Effective July 1. If your org has standalone Intune Suite add-on licenses that are now covered by M365 E3 or E5 entitlements, you may be paying for redundant licenses. Review the inclusion table in the post and coordinate with your licensing team to remove unnecessary add-ons at the next renewal or true-up.

  • ACR Stealer / ClickFix campaigns actively targeting enterprise environments [GA] - Ongoing threat. Pull Defender for Endpoint detections for ClickFix-related indicators from the documented intrusion chains. Verify that browser credential isolation and token protection controls are enabled. Escalate user awareness training if ClickFix-style lures (prompts to copy/paste PowerShell or run scripts) are not covered in your current security awareness program.