Modern Work Weekly - Week of 2026-08-18
Exchange Server SE gets its August security updates while CU1 slips further, and a wave of CVE acknowledgment updates signals an active patch cycle. Engineers also get new Defender for Identity tooling, granular Purview audit logs on the horizon, and a useful roundup of Windows device recovery options.
Top 5
Exchange Server SE August Security Updates are live and need immediate attention. Security updates are available for Exchange SE RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23. If you are on 2019 or 2016, you must also be enrolled in the Period 2 ESU program to access these SUs. Patch now.
Exchange SE CU1 has slipped again - plan your on-premises roadmap accordingly. Microsoft confirmed CU1 will not ship in H1 2026 as previously stated, and the new target is simply “second half of 2026.” AI-assisted security tooling is part of the reason cited for the delay. If you have change windows or upgrade dependencies tied to CU1, re-evaluate your timeline.
CVE-2026-59124 (HPC Pack RCE) update table corrected - verify you have the right patch. Microsoft corrected the listed software in the Security Updates table for this RCE vulnerability. If you applied a patch based on the original advisory, confirm you targeted the correct build and reapply if necessary.
Defender for Identity migration readiness now surfaces blocking reasons inline. The new tooltip on the Sensors page shows exactly why a server is marked “Not ready for migration,” which removes the guesswork when troubleshooting stalled v3 sensor migrations. If you have servers blocked on migration, check these tooltips before opening support tickets.
Purview Permissions Audit Log improvements are coming in September 2026. Enhanced audit logs will capture role and scoped-role access decisions in the Purview portal, giving admins better visibility for troubleshooting and compliance reporting. Plan to review your audit monitoring workflows when this lands.
Identity & Access
Why Active Directory alone is no longer enough [GA] - If your identity modernization case is still stalled internally, this post gives you the updated strategic framing: the question has shifted from “what can cloud do that AD cannot” to “what outcomes does a modern identity platform unlock for cloud apps and AI.” Use it to drive executive conversations about Entra ID adoption and AD dependency reduction.
How to enforce Zero Trust across every resource [GA] - This is implementation-focused guidance building on the identity-first access strategy post, covering Conditional Access and Global Secure Access deployment patterns. Key recommendations include report-only policies, emergency access exclusions, and phased rollouts to reduce risk during the transition away from VPN-based access models.
Expanded SaaS app support in Password protection (Preview) [Preview] - Password protection now surfaces password risks from SaaS apps connected through Defender for Cloud Apps, covering SSPM-enabled apps like Salesforce and ServiceNow alongside AD, Entra ID, and Okta. Each SaaS app requires an active Defender for Cloud Apps connector, so audit your connector coverage before expecting full visibility on the Password Hygiene and Password Policies tabs.
Endpoint & Device Management
- Windows device recovery in 2026: A guide for IT pros [GA] - This post consolidates the full current toolkit for Windows device recovery, from automated cloud-based fixes to full rebuilds, covering mass-scale outage scenarios, isolated disruptions, deep OS corruption, and hardware failures. If your runbooks reference older recovery procedures, use this as the authoritative baseline for what is available today and update your incident response documentation accordingly.
Collaboration & Productivity
Where is Exchange SE CU1 anyway? [GA] - CU1 has slipped from H1 2026 to a general “second half of 2026” window, with AI-assisted vulnerability discovery work cited as a contributing factor. Revisit any upgrade or change freeze dependencies tied to this release and communicate the updated timeline to stakeholders.
Released: August 2026 Exchange Server Security Updates [GA] - Security updates are out for Exchange SE RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Access to updates for 2019 and 2016 requires Period 2 ESU enrollment. Apply these as soon as possible; these address vulnerabilities found through both external security partner reporting and Microsoft’s internal AI-assisted tooling.
Turn meetings into momentum with Microsoft 365 Copilot [GA] - Microsoft’s Work Trend Index identifies inefficient meetings as the top productivity disruptor, and this post outlines current Copilot meeting capabilities: preparation, real-time assistance, catch-up for late joiners, and action item generation. Worth sharing with adoption leads driving M365 Copilot utilization metrics.
Outlook: Change the organizer of a meeting [GA] - Meeting organizer transfer is coming to Outlook for Windows, web, and Teams calendar in September 2026. The new organizer must accept before the transfer completes, preserving the existing event for all attendees. Useful for long-running recurring meetings where the original organizer has left or changed roles.
Planner: Private tasks now stored in your private plan [GA] - Private tasks across Planner and Planner-powered experiences will consolidate into a single user-owned private plan, landing in September 2026. Existing tasks continue to work alongside the new structure. No admin action needed, but be aware this changes where private tasks are stored if users or integrations reference task locations.
Microsoft Purview: eDiscovery - Select user-owned SharePoint embedded container as a data source [Preview] - eDiscovery will be able to target SharePoint Embedded content containers from Microsoft Loop, Copilot Pages, and Copilot Notebooks as custodian data sources, with preview in September 2026 and GA in October 2026. If your legal hold or eDiscovery scope needs to cover Copilot-generated content, this closes a meaningful gap.
OneDrive: Improved capabilities for files with Copilot in OneDrive Web [Preview] - Copilot file skills in OneDrive Web are being expanded to support content analysis, summarization, dashboard creation, and presentation generation directly from the file chat interface, with preview in August 2026 and GA in December. Evaluate this capability alongside your Copilot adoption strategy for knowledge workers who live in OneDrive.
Microsoft Teams: Temporarily pause all notifications [GA] - Users will be able to pause all Teams notifications temporarily, targeting September 2026. No admin configuration required; this is a user-controlled focus feature.
Microsoft Teams: Malicious URL Protection for Teams Chat and Channels for Gov clouds [GA] - Safe Links-style malicious URL detection for Teams chat and channels is coming to Government cloud customers in October 2026. Gov cloud admins should plan to review their Defender for Office 365 policy coverage for Teams when this lands.
Microsoft Teams: Specify who has control of production tools in Teams meetings and events [GA] - Organizers can now designate specific users who control production tools, including Manage What Attendees See and Green Room, rather than that access being tied solely to the organizer role. This is available now as of August 2026 and is relevant for organizations running structured internal broadcasts or large events.
OneDrive: Refreshed Libraries View in OneDrive Web [GA] - The “More places” panel in OneDrive Web has been replaced with a redesigned Libraries view that surfaces recently accessed libraries, Teams default document libraries, and favorited SharePoint sites with filtering and sorting controls. This shipped in July 2026; confirm user communications or training materials reflect the new navigation.
Microsoft Teams: SharePoint thumbnail previews [Preview] - Teams desktop now renders rich link preview cards with thumbnail images and page descriptions when SharePoint page links are shared in chat, targeting a June 2026 GA. Verify this behavior aligns with your information barrier or external sharing policies if SharePoint page previews could surface sensitive content in shared channels.
AI & Copilot
Copilot Notebooks now works with Markdown, plain-text, and rich-text files [GA] - Copilot Notebooks now accepts .md, .rtf, and .txt files as references alongside existing document types, making it practical to ground Copilot responses in READMEs, wikis, logs, and transcripts. This is live now and worth highlighting to technical and operations teams who capture knowledge in these formats.
Built for business: How Microsoft 365 Copilot keeps you in the flow of legal work [GA] - Microsoft is positioning M365 Copilot for small business legal workflow scenarios, covering contract review, document drafting, and legal resource lookup. Useful context for Copilot adoption conversations with SMB customers or internal legal and compliance teams.
Extend Liquid with Server Logic in Power Pages [GA] - Power Pages developers can now call Server Logic directly from Liquid templates, moving business logic server-side rather than relying solely on platform-provided Liquid objects. If your organization builds Power Pages portals, this expands what you can implement securely without client-side workarounds.
Your Company Is Racing to Deploy AI. Is Your Data Ready? [GA] - This post frames Dataverse as the governance foundation for AI deployments, covering capacity management, retention, security, auditing, and recovery controls. If you are deploying Copilot Studio agents or Power Platform AI solutions at scale, use this as a checklist for your Dataverse readiness review.
Microsoft 365 app: New Copilot Notebooks design in the Microsoft 365 Copilot App [Preview] - The redesigned Copilot Notebooks experience in the M365 Copilot app organizes chats, outputs, and references into a persistent workspace where accumulated context carries across sessions, with preview in July 2026 and GA targeting August 2026. This is the lightweight version; the fuller workspace experience remains in OneNote.
Security & Compliance
Defender for Identity sensor updates [GA] - Ongoing sensor update cadence for Defender for Identity; review the migration to sensor v3 documentation to ensure your sensors are current and migration prerequisites are met.
Migration readiness reasons on the Sensors page [GA] - Hovering over a server’s “Not ready for migration” status on the Sensors page now shows a tooltip listing the specific blocking prerequisites, eliminating the need to cross-reference documentation for each server. If you have servers stalled in your v3 migration, use these tooltips to triage and resolve blockers systematically.
Microsoft Purview: Permissions audit log improvements [GA] - Enhanced audit logs will capture role and scoped-role access decisions in the Purview portal, targeting GA in September 2026. Start planning how these logs will integrate into your existing SIEM ingestion and compliance reporting workflows before the feature lands.
Microsoft Purview: eDiscovery - CMK (Customer managed key) for eDiscovery direct export [GA] - Customer-managed key support for the eDiscovery direct export workflow is targeting GA in January 2027. If your data sovereignty or compliance requirements mandate CMK for exported content, this closes the gap - add it to your 2027 Purview roadmap discussions.
Microsoft 365 admin center: Organizational Data - Granular access policy controls for custom attributes [Preview] - Admins will be able to release custom organizational attributes to specific users or groups rather than all employees or all managers, and will control whether leaders can share non-public data with Workforce Insights delegates. This preview introduces a more conservative default posture for sensitive org data. Evaluate how this maps to your data governance policies when it becomes available.
CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability [GA] - Acknowledgment updated this week; no change to remediation guidance. Confirm patches applied during August Patch Tuesday are in place across your Windows estate.
CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability [GA] - Informational acknowledgment update only; remediation guidance is unchanged. Verify this was captured in your August patching cycle.
CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability [GA] - CVE description and title were corrected this week; the underlying remediation is unchanged. Confirm your vulnerability tracking tooling has picked up the corrected metadata.
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability [GA] - Acknowledgment updated; no remediation change. Ensure Office patching is current for this and the two related Office Graphics RCE CVEs below.
CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability [GA] - Acknowledgment updated; no remediation change. Part of a cluster of Office Graphics RCE vulnerabilities from August Patch Tuesday.
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability [GA] - Acknowledgment updated; no remediation change. Third in the Office Graphics RCE cluster - confirm all three are covered by your Office update deployment.
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability [GA] - Acknowledgment updated; no remediation change. If PowerShell remoting is enabled in your environment, verify this patch is applied and verify remoting exposure is scoped appropriately.
CVE-2026-58612 PowerShell Information Disclosure Vulnerability [GA] - Acknowledgment updated; no remediation change. Review alongside the PowerShell RCE CVEs as part of your overall PowerShell patch coverage validation.
CVE-2026-62886 .NET Elevation of Privilege Vulnerability [GA] - Acknowledgment updated; no remediation change. Confirm .NET runtime patching is current, particularly on servers running custom applications.
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability [GA] - Acknowledgment updated; no remediation change. Verify Word is patched to the August 2026 update level across managed endpoints.
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability [GA] - Build number for the security update was corrected; confirm your Teams desktop client version matches the corrected build number in the advisory before marking this resolved.
CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability [GA] - Build number corrected in the advisory; verify Teams iOS app version on managed devices aligns with the updated advisory before closing out remediation tracking.
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability [GA] - Build number corrected; if Azure Storage Explorer is deployed or approved in your environment, confirm the installed version matches the corrected advisory and update if needed.
CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability [GA] - Build number corrected; verify Teams for Android version on managed and BYOD devices aligns with the updated advisory. The three Teams CVE build corrections together suggest a documentation pass - recheck all three if you marked remediation complete before this week.
CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability [GA] - Microsoft corrected the software listed in the Security Updates table for this RCE and recommends installing the update as soon as possible. If you applied a patch based on the original advisory listing, verify you targeted the correct component and reapply against the corrected table.
Action Required
August 2026 Exchange Server Security Updates [GA] - Apply immediately. Patches are available for Exchange SE RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23. Organizations on 2019 or 2016 must be enrolled in the Period 2 ESU program to access the updates. Do not wait on these; the vulnerabilities include issues discovered through both external researchers and Microsoft’s internal AI-assisted security tooling.
CVE-2026-59124 HPC Pack RCE - Corrected software table [GA] - Verify patch accuracy now. Microsoft corrected the Security Updates table listing for this RCE vulnerability and recommends applying the update as soon as possible. If you previously tracked this as remediated based on the original advisory, confirm the correct component was patched.
CVE-2026-65768, CVE-2026-65769, CVE-2026-65767 Teams build number corrections [GA] - Revalidate Teams remediation tracking. Build numbers for the Teams Desktop RCE, Teams iOS information disclosure, and Teams for Android spoofing CVEs were all corrected this week. If you closed out remediation for any of these before the corrections, verify the installed app versions on desktop, iOS managed devices, and Android managed/BYOD devices align with the now-corrected advisory build numbers.
Documentation Updates
Identity & Access
New how-to guide for migrating web content filtering policies to v2 - A new article documenting the migration process for Global Secure Access web content filtering policies to the v2 policy model has been added; if you are managing web content filtering through Entra, review this guide before your next policy change.
Conditional Access account recovery FAQ added - A new FAQ page covering account recovery scenarios under Conditional Access policies has been published; useful reference for helpdesk and identity teams handling lockout escalations.
Attacker-added device risk remediation guidance revised - The guidance for remediating the attacker-added device risk detection in Entra ID has been meaningfully rewritten; if your team references this doc in incident response runbooks, update your local copies.
Agent Identity anti-pattern guidance and AI coding assistant guardrails added - The Entra Agent Identity developer docs now include explicit anti-pattern guidance and guardrails for teams using AI coding assistants to build agent authentication flows; relevant for any team building Copilot Studio or custom agents with Entra-backed identities.
Endpoint & Device Management
Intune daily Device Action limits now documented - Daily per-tenant limits on Intune Device Actions are now formally documented; if you run large-scale automated remediation or bulk device actions, review these limits to avoid throttling in production workflows.
BitLocker migration group reuse considerations added - A new section covering group reuse scenarios in BitLocker migration has been added to the migration considerations doc; relevant for environments moving BitLocker management into Intune from GPO or MBAM.
Sources
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40400
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56188
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62722
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66807
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63519
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63513
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70337
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58612
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62886
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63518
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65768
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65769
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57104
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65767
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59124
- https://learn.microsoft.com/en-us/defender-for-identity/deploy/migrate-to-sensor-v3
- https://learn.microsoft.com/en-us/defender-for-identity/deploy/migrate-to-sensor-v3#troubleshoot-not-ready-for-migration-status
- https://www.microsoft.com/microsoft-365/roadmap?id=569363
- https://www.microsoft.com/microsoft-365/roadmap?id=565373
- https://www.microsoft.com/microsoft-365/roadmap?id=564805
- https://techcommunity.microsoft.com/t5/microsoft-entra-blog/why-active-directory-alone-is-no-longer-enough/ba-p/4546402
- https://techcommunity.microsoft.com/t5/microsoft-entra-blog/how-to-enforce-zero-trust-across-every-resource/ba-p/4529305
- https://learn.microsoft.com/en-us/defender-for-identity/password-protection
- https://techcommunity.microsoft.com/t5/exchange-team-blog/where-is-exchange-se-cu1-anyway/ba-p/4546837
- https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2026-exchange-server-security-updates/ba-p/4543951
- https://techcommunity.microsoft.com/t5/microsoft-teams-blog/turn-meetings-into-momentum-with-microsoft-365-copilot/ba-p/4545675
- https://www.microsoft.com/microsoft-365/roadmap?id=569431
- https://www.microsoft.com/microsoft-365/roadmap?id=569426
- https://www.microsoft.com/microsoft-365/roadmap?id=569364
- https://www.microsoft.com/microsoft-365/roadmap?id=569215
- https://www.microsoft.com/microsoft-365/roadmap?id=569205
- https://www.microsoft.com/microsoft-365/roadmap?id=569421
- https://www.microsoft.com/microsoft-365/roadmap?id=567305
- https://www.microsoft.com/microsoft-365/roadmap?id=566315
- https://www.microsoft.com/microsoft-365/roadmap?id=561321
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/copilot-notebooks-now-works-with-markdown-plain-text-and-rich/ba-p/4545652
- https://techcommunity.microsoft.com/t5/microsoft-365-copilot-blog/built-for-business-how-microsoft-365-copilot-keeps-you-in-the/ba-p/4546016
- https://www.microsoft.com/en-us/power-platform/blog/power-pages/extend-liquid-with-server-logic-in-power-pages/
- https://www.microsoft.com/en-us/power-platform/blog/2026/08/11/your-company-is-racing-to-deploy-ai-is-your-data-ready/
- https://www.microsoft.com/microsoft-365/roadmap?id=562662
- https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-device-recovery-in-2026-a-guide-for-it-pros/ba-p/4541207
