Modern Work Weekly - Week of 2026-08-25
Purview gets two meaningful compliance additions this week - retention for Copilot Memory and DSI integration with endpoint DLP alerts - plus expanded Organizational Messages support for hybrid-joined devices.
Top 5
Purview retention for Copilot Memory (GA) - Copilot memory items live in a hidden Exchange mailbox folder. Now you can apply retention and versioning to those items, which matters for eDiscovery, compliance investigations, and any regulatory requirement that extends to AI-generated context. Start planning your retention policies to include this data class before users accumulate significant memory history.
Data Security Investigations launches from endpoint DLP alerts (Preview) - Instead of pivoting manually between DLP alerts and investigation workflows, analysts can now jump directly from an endpoint DLP alert into a DSI session pre-scoped to the relevant files, users, and time range. GA is September 2026; the preview is live now, so security teams should validate the workflow before it ships broadly.
Organizational Messages now supports hybrid-joined devices (Preview) - This closes a gap that forced many organizations to choose between Organizational Messages and their hybrid estate. If you manage hybrid-joined devices and have been waiting on this, the preview is available now with GA in June 2026.
Purview Data Lifecycle Management: Retention for Copilot Memory (GA) - Inactive memory versions are preserved and versioned in the user’s Exchange mailbox, giving admins visibility into memory changes over time. Compliance and legal teams should be briefed now so they can incorporate Copilot memory into hold and retention scope decisions.
Ask Microsoft Anything: David Weston on Agentic Security - Weston leads frontier security model training, agentic defender systems, and AI-driven vulnerability discovery at Microsoft. If your team is evaluating AI security tooling or thinking through agentic risk posture, the recording is worth your time.
Security & Compliance
Reminder: Ask Microsoft Anything with David Weston [GA] - Weston leads Agentic Security at Microsoft, covering frontier security model training, autonomous defender agents, and AI-driven vulnerability discovery. His background spans exploit mitigation, APT research, and security engineering for Windows, Xbox, and Azure OS. Catch the recording if your team is working through agentic AI risk or evaluating AI-assisted defense tooling.
Microsoft Purview: Data Security Investigations - analyze files tied to endpoint DLP alerts [Preview] - DSI can now be launched directly from an endpoint DLP alert, automatically scoping the investigation to the files, users, endpoints, and time range that triggered the alert. This cuts the manual pivot between DLP alert triage and file-level investigation. Preview is live now; GA is targeted for September 2026, so run a pilot with your SOC team ahead of that date.
Microsoft 365 admin center: Organizational Messages now supports Hybrid-joined Devices [Preview] - Hybrid-joined devices can now receive Organizational Messages, removing the coverage gap that excluded them from targeted communications delivered via the admin center. Preview is available now; GA is June 2026. Organizations with mixed Azure AD join and hybrid-join estates should test targeting scenarios in preview to confirm expected reach before GA.
Microsoft Purview: Data Lifecycle Management - Retention for Copilot Memory [GA] - Retention and versioning now apply to Copilot memory items stored in users’ Exchange mailboxes, including saved memories and context inferred from chat history. Inactive memory versions are preserved so admins can track changes while active memory continues to be managed by Copilot. Update your DLM policies and inform legal and compliance stakeholders that Copilot memory is now a retainable data class.
Action Required
No CVEs were included in this week’s data. The items below are the highest-priority actions from this digest for the next 30 days.
Purview DSI for Endpoint DLP Alerts - Preview validation - GA lands September 2026. Run a pilot with your security team now to validate analyst workflows and ensure your endpoint DLP policies surface the right alert context before the feature ships broadly.
Retention for Copilot Memory - Policy review - This feature is GA. Review existing retention policies to determine whether Copilot memory scope needs to be added, and brief legal and compliance teams on the new data class before it accumulates history at scale.
Organizational Messages for Hybrid-joined Devices - Preview testing - GA is June 2026. If you manage a hybrid estate, enroll in preview now and validate targeting, delivery, and reporting behavior against your device population before GA rollout.
Documentation Updates
Identity & Access
New article: SAMAccountName attribute reference for Entra ID - A new article documents SAMAccountName behavior in Entra ID, relevant for hybrid environments where attribute sync and legacy authentication intersect.
Lifecycle Workflows: clone an existing workflow - Docs now cover how to clone an existing Lifecycle Workflow, useful for teams standing up parallel joiner/mover/leaver flows without rebuilding from scratch.
Lifecycle Workflows: relative time-based triggers documented - New guidance covers relative time-based workflow triggers (for example, N days before or after an attribute date), which expands the automation options for lifecycle event handling.
Global Secure Access macOS client documentation updated - Updated release history and client guidance for the Global Secure Access macOS client; check if your macOS deployment notes need to be revised against the new content.
SSO for Linux devices: updated guidance - Microsoft SSO for Linux device documentation has been revised; engineers deploying Entra SSO to Linux endpoints should review for any changed prerequisites or configuration steps.
Endpoint & Device Management
- Defender catch-up scan behavior updated in docs - Documentation covering Defender catch-up scan settings has been updated; review if your Intune antivirus policy relies on catch-up scan configuration to confirm your settings match the documented behavior.
Sources
- https://techcommunity.microsoft.com/t5/microsoft-security-community/reminder-ask-microsoft-anything-with-david-weston-is-tomorrow-8/ba-p/4549690
- https://www.microsoft.com/microsoft-365/roadmap?id=558547
- https://www.microsoft.com/microsoft-365/roadmap?id=503564
- https://www.microsoft.com/microsoft-365/roadmap?id=569612
- https://github.com/MicrosoftDocs/entra-docs/commit/229b71bc1380356061995fe528eca7c58b025bf1
- https://github.com/MicrosoftDocs/entra-docs/commit/58c21f91283136b2713d310cf3c810d3ee6a7e9f
- https://github.com/MicrosoftDocs/entra-docs/commit/ecd837b3898d4fd03bc8f320b0013b41a8fe10e5
- https://github.com/MicrosoftDocs/entra-docs/commit/2f521761794eb9f4eb0da671db264906dd841883
- https://github.com/MicrosoftDocs/memdocs/commit/439f9830c3d3114e08646bcb25286bece432895c
