Top 5

  1. Exchange Server SE August Security Updates are live and need immediate attention. Security updates are available for Exchange SE RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23. If you are on 2019 or 2016, you must also be enrolled in the Period 2 ESU program to access these SUs. Patch now.

  2. Exchange SE CU1 has slipped again - plan your on-premises roadmap accordingly. Microsoft confirmed CU1 will not ship in H1 2026 as previously stated, and the new target is simply “second half of 2026.” AI-assisted security tooling is part of the reason cited for the delay. If you have change windows or upgrade dependencies tied to CU1, re-evaluate your timeline.

  3. CVE-2026-59124 (HPC Pack RCE) update table corrected - verify you have the right patch. Microsoft corrected the listed software in the Security Updates table for this RCE vulnerability. If you applied a patch based on the original advisory, confirm you targeted the correct build and reapply if necessary.

  4. Defender for Identity migration readiness now surfaces blocking reasons inline. The new tooltip on the Sensors page shows exactly why a server is marked “Not ready for migration,” which removes the guesswork when troubleshooting stalled v3 sensor migrations. If you have servers blocked on migration, check these tooltips before opening support tickets.

  5. Purview Permissions Audit Log improvements are coming in September 2026. Enhanced audit logs will capture role and scoped-role access decisions in the Purview portal, giving admins better visibility for troubleshooting and compliance reporting. Plan to review your audit monitoring workflows when this lands.

Identity & Access

  • Why Active Directory alone is no longer enough [GA] - If your identity modernization case is still stalled internally, this post gives you the updated strategic framing: the question has shifted from “what can cloud do that AD cannot” to “what outcomes does a modern identity platform unlock for cloud apps and AI.” Use it to drive executive conversations about Entra ID adoption and AD dependency reduction.

  • How to enforce Zero Trust across every resource [GA] - This is implementation-focused guidance building on the identity-first access strategy post, covering Conditional Access and Global Secure Access deployment patterns. Key recommendations include report-only policies, emergency access exclusions, and phased rollouts to reduce risk during the transition away from VPN-based access models.

  • Expanded SaaS app support in Password protection (Preview) [Preview] - Password protection now surfaces password risks from SaaS apps connected through Defender for Cloud Apps, covering SSPM-enabled apps like Salesforce and ServiceNow alongside AD, Entra ID, and Okta. Each SaaS app requires an active Defender for Cloud Apps connector, so audit your connector coverage before expecting full visibility on the Password Hygiene and Password Policies tabs.

Endpoint & Device Management

  • Windows device recovery in 2026: A guide for IT pros [GA] - This post consolidates the full current toolkit for Windows device recovery, from automated cloud-based fixes to full rebuilds, covering mass-scale outage scenarios, isolated disruptions, deep OS corruption, and hardware failures. If your runbooks reference older recovery procedures, use this as the authoritative baseline for what is available today and update your incident response documentation accordingly.

Collaboration & Productivity

  • Where is Exchange SE CU1 anyway? [GA] - CU1 has slipped from H1 2026 to a general “second half of 2026” window, with AI-assisted vulnerability discovery work cited as a contributing factor. Revisit any upgrade or change freeze dependencies tied to this release and communicate the updated timeline to stakeholders.

  • Released: August 2026 Exchange Server Security Updates [GA] - Security updates are out for Exchange SE RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Access to updates for 2019 and 2016 requires Period 2 ESU enrollment. Apply these as soon as possible; these address vulnerabilities found through both external security partner reporting and Microsoft’s internal AI-assisted tooling.

  • Turn meetings into momentum with Microsoft 365 Copilot [GA] - Microsoft’s Work Trend Index identifies inefficient meetings as the top productivity disruptor, and this post outlines current Copilot meeting capabilities: preparation, real-time assistance, catch-up for late joiners, and action item generation. Worth sharing with adoption leads driving M365 Copilot utilization metrics.

  • Outlook: Change the organizer of a meeting [GA] - Meeting organizer transfer is coming to Outlook for Windows, web, and Teams calendar in September 2026. The new organizer must accept before the transfer completes, preserving the existing event for all attendees. Useful for long-running recurring meetings where the original organizer has left or changed roles.

  • Planner: Private tasks now stored in your private plan [GA] - Private tasks across Planner and Planner-powered experiences will consolidate into a single user-owned private plan, landing in September 2026. Existing tasks continue to work alongside the new structure. No admin action needed, but be aware this changes where private tasks are stored if users or integrations reference task locations.

  • Microsoft Purview: eDiscovery - Select user-owned SharePoint embedded container as a data source [Preview] - eDiscovery will be able to target SharePoint Embedded content containers from Microsoft Loop, Copilot Pages, and Copilot Notebooks as custodian data sources, with preview in September 2026 and GA in October 2026. If your legal hold or eDiscovery scope needs to cover Copilot-generated content, this closes a meaningful gap.

  • OneDrive: Improved capabilities for files with Copilot in OneDrive Web [Preview] - Copilot file skills in OneDrive Web are being expanded to support content analysis, summarization, dashboard creation, and presentation generation directly from the file chat interface, with preview in August 2026 and GA in December. Evaluate this capability alongside your Copilot adoption strategy for knowledge workers who live in OneDrive.

  • Microsoft Teams: Temporarily pause all notifications [GA] - Users will be able to pause all Teams notifications temporarily, targeting September 2026. No admin configuration required; this is a user-controlled focus feature.

  • Microsoft Teams: Malicious URL Protection for Teams Chat and Channels for Gov clouds [GA] - Safe Links-style malicious URL detection for Teams chat and channels is coming to Government cloud customers in October 2026. Gov cloud admins should plan to review their Defender for Office 365 policy coverage for Teams when this lands.

  • Microsoft Teams: Specify who has control of production tools in Teams meetings and events [GA] - Organizers can now designate specific users who control production tools, including Manage What Attendees See and Green Room, rather than that access being tied solely to the organizer role. This is available now as of August 2026 and is relevant for organizations running structured internal broadcasts or large events.

  • OneDrive: Refreshed Libraries View in OneDrive Web [GA] - The “More places” panel in OneDrive Web has been replaced with a redesigned Libraries view that surfaces recently accessed libraries, Teams default document libraries, and favorited SharePoint sites with filtering and sorting controls. This shipped in July 2026; confirm user communications or training materials reflect the new navigation.

  • Microsoft Teams: SharePoint thumbnail previews [Preview] - Teams desktop now renders rich link preview cards with thumbnail images and page descriptions when SharePoint page links are shared in chat, targeting a June 2026 GA. Verify this behavior aligns with your information barrier or external sharing policies if SharePoint page previews could surface sensitive content in shared channels.

AI & Copilot

  • Copilot Notebooks now works with Markdown, plain-text, and rich-text files [GA] - Copilot Notebooks now accepts .md, .rtf, and .txt files as references alongside existing document types, making it practical to ground Copilot responses in READMEs, wikis, logs, and transcripts. This is live now and worth highlighting to technical and operations teams who capture knowledge in these formats.

  • Built for business: How Microsoft 365 Copilot keeps you in the flow of legal work [GA] - Microsoft is positioning M365 Copilot for small business legal workflow scenarios, covering contract review, document drafting, and legal resource lookup. Useful context for Copilot adoption conversations with SMB customers or internal legal and compliance teams.

  • Extend Liquid with Server Logic in Power Pages [GA] - Power Pages developers can now call Server Logic directly from Liquid templates, moving business logic server-side rather than relying solely on platform-provided Liquid objects. If your organization builds Power Pages portals, this expands what you can implement securely without client-side workarounds.

  • Your Company Is Racing to Deploy AI. Is Your Data Ready? [GA] - This post frames Dataverse as the governance foundation for AI deployments, covering capacity management, retention, security, auditing, and recovery controls. If you are deploying Copilot Studio agents or Power Platform AI solutions at scale, use this as a checklist for your Dataverse readiness review.

  • Microsoft 365 app: New Copilot Notebooks design in the Microsoft 365 Copilot App [Preview] - The redesigned Copilot Notebooks experience in the M365 Copilot app organizes chats, outputs, and references into a persistent workspace where accumulated context carries across sessions, with preview in July 2026 and GA targeting August 2026. This is the lightweight version; the fuller workspace experience remains in OneNote.

Security & Compliance

Action Required

  • August 2026 Exchange Server Security Updates [GA] - Apply immediately. Patches are available for Exchange SE RTM, Exchange Server 2019 CU14/CU15, and Exchange Server 2016 CU23. Organizations on 2019 or 2016 must be enrolled in the Period 2 ESU program to access the updates. Do not wait on these; the vulnerabilities include issues discovered through both external researchers and Microsoft’s internal AI-assisted security tooling.

  • CVE-2026-59124 HPC Pack RCE - Corrected software table [GA] - Verify patch accuracy now. Microsoft corrected the Security Updates table listing for this RCE vulnerability and recommends applying the update as soon as possible. If you previously tracked this as remediated based on the original advisory, confirm the correct component was patched.

  • CVE-2026-65768, CVE-2026-65769, CVE-2026-65767 Teams build number corrections [GA] - Revalidate Teams remediation tracking. Build numbers for the Teams Desktop RCE, Teams iOS information disclosure, and Teams for Android spoofing CVEs were all corrected this week. If you closed out remediation for any of these before the corrections, verify the installed app versions on desktop, iOS managed devices, and Android managed/BYOD devices align with the now-corrected advisory build numbers.

Documentation Updates

Identity & Access

Endpoint & Device Management

  • Intune daily Device Action limits now documented - Daily per-tenant limits on Intune Device Actions are now formally documented; if you run large-scale automated remediation or bulk device actions, review these limits to avoid throttling in production workflows.

  • BitLocker migration group reuse considerations added - A new section covering group reuse scenarios in BitLocker migration has been added to the migration considerations doc; relevant for environments moving BitLocker management into Intune from GPO or MBAM.