Top 5

  1. Defender for Office 365 Plan 1 now included in Microsoft 365 E3 - If your organization is on E3, you just gained anti-phishing, safe links, safe attachments, and real-time detections without an additional license purchase. Audit what you were paying for separately and update your security baseline accordingly.

  2. Writeback for Cloud-Managed Remote Mailboxes hits GA - The critical milestone for retiring your last on-premises Exchange server is here. Writeback is live in WW, GCCH, DoD, and 21Vianet, supporting up to 600,000 cloud-managed mailboxes per tenant. If you have been waiting on this to pull the plug on your last Exchange box, the blocker is gone.

  3. CaptiveCrunch: Midnight Blizzard actively targeting hospitality sign-in portals - Storm-2945 has been compromising hotel and hospitality sign-in portals since May 2026 to deliver malware and steal credentials from travelers. If your users travel frequently or your org is in the hospitality sector, review your conditional access policies and endpoint posture for travel scenarios now.

  4. Unified RBAC is now the default for new Defender for Office 365 Plan 2 orgs - Starting July 2026, any new MDO Plan 2 tenant lands on Microsoft Defender Unified RBAC by default. Existing tenants are not automatically migrated, but this is the direction of travel: review MC1246006 and plan your RBAC migration if you are still on the legacy model.

  5. Domain Exclusion for Microsoft 365 Copilot is GA - Admins can now explicitly block specific external domains from being used as web grounding sources in Copilot responses. This is a meaningful compliance and data governance control for organizations in regulated industries or with strict trusted-source policies.

Identity & Access

  • Give Every AI Agent Its Own Identity [GA] - Microsoft Entra Agent ID provides each AI agent a unique, managed identity so you can apply visibility, governance, and Zero Trust controls to non-human actors the same way you do for users. Agents with broad permissions are a high-value target: a misconfigured or compromised agent can traverse your environment at machine speed. Start inventorying agents in your tenant and assigning least-privilege identities through Entra Agent ID.

  • Writeback for Cloud-Managed Remote Mailboxes: Now Generally Available [GA] - Writeback allows Exchange Online to hold the Source of Authority for Exchange attributes on directory-synced mailboxes, eliminating the last dependency that keeps many orgs tethered to on-premises Exchange. Available now in WW, GCCH, DoD, and 21Vianet for up to 600,000 mailboxes per tenant. If retiring your last Exchange server is on the roadmap, this is the GA signal to move that project off hold.

  • Microsoft Teams: View and manage auto attendant shared voicemails directly in the Queues app [GA] - Auto Attendant calls routed to voicemail will now surface directly in the Queues app, giving contact center and telephony teams a centralized place to track and respond. Targeting August 2026 GA; validate that your Queues app deployment and Auto Attendant routing configurations are in place before rollout.

Endpoint & Device Management

  • What’s new in Microsoft Intune - July [GA] - This month’s Intune release centers on visibility and troubleshooting confidence, headlined by improved Windows device sync status surfacing so admins can diagnose sync issues faster without guesswork. Review the full July changelog and cross-reference against your current compliance and configuration policies to catch any behavioral changes before they hit your fleet.

Collaboration & Productivity

  • What’s New in Microsoft Teams | April 2026 [GA] - The April Teams roundup covers AI-enhanced collaboration, calling improvements, and hybrid meeting enhancements from M365 Community Conference. If your team did not review this at release, cross-check the feature list against your Teams policies and governance controls.

  • From AI Experiments to Digital Workforce: Do Enterprises Need a Chief Agent Officer? [GA] - As agent fleets grow, ownership is fragmenting across IT, security, and compliance with no clear accountability model. This piece frames the governance gap around AI agents that can access enterprise data, invoke tools, and act autonomously. Use this as a conversation-starter with leadership about establishing a formal agent governance model before the sprawl becomes unmanageable.

  • Writeback for Cloud-Managed Remote Mailboxes: Now in Public Preview [Preview] - Note: this item has since reached GA (see Identity & Access section). The public preview post remains useful context for the full writeback journey and community feedback that shaped the GA release.

  • What’s New in Microsoft 365 Copilot | July 2026 [GA] - July’s Copilot update delivers agent additions in Copilot Chat, model updates in the Copilot app and Cowork, expanded reference support in Copilot Notebooks, new Word skills, and Power Platform integrations. Review the full feature list against your Copilot deployment and ensure users are aware of new capabilities relevant to their workflows.

  • What’s New in Microsoft Teams | July 2026 [GA] - July Teams highlights include the new Meeting Recaps app for finding and catching up on past meetings, and improved app and agent management controls for IT. Review the Meeting Recaps app rollout timeline and update your Teams app governance policies to account for the new agent management capabilities.

  • What’s new in Microsoft Security: July 2026 [GA] - The July security roundup covers AI environment security, AI-assisted defense tooling, and foundational hardening for AI-powered operations. Worth a read for security and IT leads to align on which new capabilities are relevant to your current roadmap.

  • Localized default Mark as and notify email templates [GA] - When using the default admin notification template for user-reported messages, users now receive emails in their Outlook preferred language automatically. Custom admin-configured templates are not affected, so no action is required if you have customized these templates already.

  • Unified RBAC is the default permission model for new Defender for Office 365 Plan 2 organizations [GA] - Starting July 2026, new MDO Plan 2 tenants land on Unified RBAC by default. Existing orgs are not auto-migrated, but this is the long-term direction: review MC1246006, assess your current RBAC model, and plan migration to avoid being on a legacy permission model as feature development focuses on Unified RBAC.

  • Microsoft Defender for Office 365 Plan 1 included in Microsoft 365 E3 [GA] - MDO Plan 1 is now bundled into M365 E3 at no additional cost. Check whether your E3 users are currently covered by a separate MDO Plan 1 license purchase, and reconcile your license spend accordingly. Confirm that the Plan 1 capabilities are active and properly configured for your E3 user population.

  • Prompt injection protection [GA] - Defender for Office 365 now detects prompt injection attacks hidden in inbound email, an increasingly relevant threat as employees use email-connected AI tools. Verify this detection capability is enabled in your anti-phishing and email threat policies and confirm your SOC knows what alert signals to expect.

  • SharePoint Showcase: 10 Custom AI Skills Every SharePoint Site Owner Should Build [GA] - Copilot skills in SharePoint let teams define reusable natural-language instructions for recurring tasks like summarizing meetings, generating reports, and reviewing documents, persisted at the site level. If you are rolling out Copilot for Microsoft 365, this is a practical guide to help site owners drive consistent, high-quality AI usage within their teams.

  • Dataverse Plugin for Coding Agents: OpenAI and Codex Marketplace Expansion [GA] - The Dataverse plugin is now available in the OpenAI and Codex agent marketplaces, extending Dataverse connectivity to developers working outside the Microsoft toolchain. Assess whether this opens new data access paths that require governance or DLP policy updates in your environment.

  • Microsoft Teams: See more messages on mobile [GA] - A streamlined mobile messaging layout will display more content on screen with improved readability, targeting September 2026 GA. No admin action required, but surface this to your Teams champions so users are not surprised by the layout change.

  • Microsoft Teams: Updated header and dashboard for chats and channels on mobile [GA] - A redesigned channel header and lightweight dashboard on Teams mobile brings channel details, people, and pinned content into a single view, aligning mobile and desktop experiences more closely. Targeting September 2026 GA; communicate the change to end users ahead of rollout to reduce support tickets.

  • Microsoft Teams: Clearer text highlighting in dark mode [GA] - Highlighted text rendering in dark mode composition has been improved for consistency. Targeting September 2026 GA; no admin action required.

  • Microsoft Teams: Teams shared display mode and peripheral detection available for DoD environments [GA] - Shared display mode for private meeting hosting from a PC and BYOD peripheral detection for the Pro Management portal are now available in Teams for DoD, targeting August 2026 GA. DoD admins should validate their Pro Management portal configuration and confirm peripheral inventory reporting is working as expected.

  • Microsoft Teams: Ability for IT admins to customize user notification messages for recording and transcription in calls [GA] - Admins will be able to customize the user-facing notification message text for recording and transcription during Teams calls, targeting August 2026 GA. Prepare your custom notification language now, especially if your organization has legal or compliance requirements around recording disclosures.

  • Microsoft Teams: Enhanced delegated calling with delegate call access restrictions and join notifications [GA] - Delegators can now lock an active call to prevent delegates from joining or resuming it, and can enable warning tones when a delegate joins. Targeting August 2026 GA; brief your telephony admins and delegator user group on the new controls, particularly in executive assistant and legal scenarios where call privacy matters.

  • Planner: Task Details Side Pane experience [GA] - Task details now open in a side pane rather than a modal dialog, keeping your Board, Grid, or My Tasks view visible while editing. This was targeted for July 2026 GA and should already be rolling out; no admin action required.

  • SharePoint: Admin Center detailed report on Everyone except external user permissions [GA] - SharePoint Advanced Management admins now get an item-level permissions report covering the “Everyone except external users” and “Everyone” special groups, targeting August 2026 GA. If broad-access permissions are a compliance concern in your tenant, prioritize reviewing this report once it lands and remediate overshared content.

AI & Copilot

  • Why Ungoverned AI Agents Are Dangerous [GA] - AI semantic search can surface previously hard-to-find data, and agents with broad permissions can move through an organization at speeds that make manual detection ineffective. This is a useful framing resource for security awareness conversations with stakeholders who underestimate agent risk.

  • The next measure of AI momentum is work transformed [GA] - Microsoft 365 Copilot has surpassed 30 million paid seats with net seat adds more than doubling quarter over quarter. Adoption at this scale means your users are likely encountering Copilot in more contexts: make sure your data governance and sensitivity labeling posture is solid before broader rollout compounds any existing oversharing issues.

  • Prompt Columns in GA: Turning Business Apps Data into Persisted AI Insights [GA] - Power Platform Prompt Columns allow natural-language prompts to be embedded directly in Dataverse tables, with AI-generated outputs persisted in the data. Evaluate whether Prompt Columns need to be governed under your existing AI and data classification policies, particularly for tables containing sensitive business data.

  • Microsoft Viva: Viva Glint - Copilot admin configuration assistance [GA] - A Copilot-powered conversational assistant embedded in the Viva Glint admin experience will answer configuration and how-to questions with deep links to settings pages, targeting September 2026 GA. Available only to Glint users with Admin permissions; no broader data access concerns, but confirm it is on your radar if you manage Glint.

Security & Compliance

Action Required

  • CaptiveCrunch threat campaign (active, ongoing): Storm-2945 / Midnight Blizzard has been actively compromising hospitality sign-in portals since May 2026. Review the campaign details and update conditional access policies for travel and untrusted network scenarios. Ensure your threat hunting rules cover indicators from this campaign. If your org is in the hospitality sector, treat your sign-in infrastructure as actively targeted.

  • Trusted Launch as Default - one-time registration required for IaC tooling: TLaD is GA and active for Portal, PowerShell, and CLI, but ARM templates, Bicep, Terraform, and SDK-based deployments require a one-time opt-in registration. Complete this registration now to avoid deploying Gen2 VMs without Secure Boot and vTPM from your automation pipelines.

  • MDO Plan 1 now included in M365 E3 - reconcile licensing: Microsoft Defender for Office 365 Plan 1 is now bundled in M365 E3. If you purchased MDO Plan 1 as an add-on for E3 users, audit your license inventory and remove redundant add-on licenses to recover spend. Also confirm that MDO Plan 1 capabilities are properly activated for your E3 population.

  • SharePoint Advanced Management - “Everyone except external users” permissions report (August 2026): The new item-level permissions report targeting August GA will expose exactly which content has been shared broadly via the “Everyone except external users” and “Everyone” groups. Assign an owner now to review and act on findings at launch; broad-access permissions are a common compliance finding and this report removes the audit gap.

  • Unified RBAC for Defender for Office 365 Plan 2 - migration planning: New orgs default to Unified RBAC from July 2026. Existing orgs are not auto-migrated, but MDO feature investment is tracking toward Unified RBAC. Review MC1246006, configure Unified RBAC for MDO, and schedule your migration before legacy model support erodes.

  • Teams call recording/transcription notification customization (August 2026): Admin-customizable notification messages for recording and transcription disclosures are GA in August. If your organization has legal or compliance requirements around how recording consent is communicated, draft and test your custom notification text before the feature lands.

Documentation Updates

Identity & Access

Endpoint & Device Management

Security & Compliance