Modern Work Weekly - Week of 2026-09-01
Autopilot device association reaches GA with hardware-backed pre-enrollment trust, Remote Help gets unattended Windows access, and two Critical-severity CVEs land alongside a heads-up from Exchange Online that legacy identifier properties may be on their way out.
Top 5
Autopilot Device Association is GA - Hardware-backed attestation now lets you bind a physical Windows 11 device to your tenant before enrollment begins, closing the gap where policy and identity couldn’t reach a device until after a user signed in. This is the foundation for zero-touch provisioning with verified device identity, and it lands in production this month.
Remote Help Unattended Support is GA - Helpdesk staff can now remotely access physical Windows devices without the end user being present, including with remote sign-in. Shared devices, after-hours maintenance, and remote-office scenarios no longer require scheduling around user availability.
CVE-2026-62823: Critical Windows DHCP Server RCE (CVSS 8.8) - A Critical-severity remote code execution vulnerability in Windows DHCP Server is patched. Any internet- or network-adjacent DHCP server exposure raises the blast radius here; verify patching is complete across your Windows Server estate.
CVE-2026-62889: Critical Windows SSTP RCE (CVSS 8.1) - Secure Socket Tunneling Protocol stacks are an RCE target with this Critical patch. If you’re running SSTP-based VPN infrastructure on Windows Server, confirm this update is applied before your next maintenance window.
Exchange Online identifier deprecation survey - The Exchange team is evaluating the future of ObjectGuid, SamAccountName, and DistinguishedName in Exchange Online as part of directory modernization. If your automation, scripts, or integrations depend on any of these, respond to their survey now before decisions are finalized.
Identity & Access
- Instant revocation of service principal bearer tokens with CAE [GA] - If you have incident response playbooks that revolve around compromised service principals, this is the capability you’ve been waiting for: Continuous Access Evaluation can now instantly invalidate access tokens for service principals using the Client Credential flow. Wire this into your kill-switch runbooks for any privileged workload identity, and ensure those principals are CAE-capable.
Endpoint & Device Management
What’s new in Microsoft Intune - August [GA] - The August Intune release centers on the full device lifecycle: Autopilot device association, unattended Remote Help, and Apple device settings prep all land this month. Review the full changelog for any new policy surfaces relevant to your managed estate.
Introducing device association for Windows Autopilot device preparation [GA] - Device association uses hardware-backed attestation to bind a Windows 11 device to your tenant before enrollment, meaning the right policies and experience are delivered regardless of who signs in first. This is now GA for Autopilot device preparation, and replaces the previous dependency on post-enrollment identity confirmation. Plan your provisioning workflow updates accordingly.
Remote Help on Windows: Unattended Support with Remote Sign-In Is Here [GA] - Helpdesk staff can now remotely connect to physical Windows devices without the user present, and sign in remotely to complete troubleshooting or maintenance tasks. This removes the scheduling bottleneck for shared-device environments, call centers, and unmanned remote-office endpoints. Confirm your Remote Help licensing covers unattended access before enabling for helpdesk teams.
The patch window is collapsing: Why security needs a new control plane [GA] - Microsoft Security’s perspective on the shrinking time between vulnerability disclosure and exploitation, and the argument for compensating controls that operate between discovery and patch deployment. Read this as strategic context for your vulnerability management posture, particularly if you rely solely on patch cadence as your primary control.
Collaboration & Productivity
Upcoming changes to classic experiences in SharePoint Online [GA] - Microsoft is formally deprecating classic SharePoint publishing and UX extensibility features, ten years after the modern framework launched. If your intranet or custom portals still use classic publishing pages, classic master pages, or classic web parts, now is the time to inventory and plan migration. Read the full Learn article for specific timelines and FAQs before they turn into surprises.
Tell us how you use ObjectGuid, SamAccountName, and DistinguishedName in Exchange Online [GA] - The Exchange team is actively evaluating whether to retire or consolidate these legacy identifier properties as part of multi-year directory modernization. If any of your automation, PowerShell scripts, connectors, or third-party integrations resolve Exchange objects by ObjectGuid, SamAccountName, or DistinguishedName, submit your use case to the survey now. This is the window to influence the outcome before decisions are made.
Copilot Fixes Your Double-Booked Calendar [GA] - Copilot in Outlook uses Work IQ to analyze schedule conflicts and recommend which meetings to reschedule, who to notify, and what actions to take. Worth flagging to users as a practical adoption entry point for Copilot in daily workflow.
SharePoint Showcase: 5 Ways Organizations Improve Business Processes with Copilot in SharePoint [GA] - Real-world patterns for using Copilot in SharePoint to summarize content, compare documents, and build reusable skills from repeatable processes. Useful reference material when scoping Copilot adoption projects or briefing business stakeholders.
Copilot Drafts Word Docs With Sensitivity Labels [GA] - Copilot in Word now automatically applies sensitivity labels when drafting documents, based on the content it pulls from SharePoint, OneDrive, meetings, and Teams. Verify your information protection policies are correctly scoped and that auto-labeling rules reflect your intended classification outcomes before users encounter this behavior at scale.
What Is Work IQ in Microsoft 365? [GA] - Work IQ is Microsoft’s term for the knowledge and context layer underlying Microsoft 365 Copilot and agents, spanning SharePoint, email, Teams, Dynamics 365, and Power Apps. If you’re planning Copilot governance or data boundary controls, understanding what Work IQ indexes is foundational.
Streamlining Enterprise Collaboration - ACP - SharePoint Partner Spotlight [GA] - Partner-built solutions on SharePoint and M365 for accelerating intranet modernization and improving information architecture ahead of Copilot adoption. Informational; relevant if you’re evaluating ISV solutions to close intranet readiness gaps.
Turn conversations into code with GitHub Copilot in Microsoft Teams [GA] - GitHub Copilot can now be @mentioned directly in Teams channels, letting developers act on decisions in the conversation without switching context to a separate tool. This requires GitHub Copilot licensing and Teams app enablement; evaluate whether your developer population and app governance policies need updating before it spreads organically.
SharePoint: Site Skills in Copilot in SharePoint [GA] - Site Skills in Copilot for SharePoint now supports skill editing, version control, publishing, restoration, and cross-site duplication, giving admins governance controls over reusable Copilot skills across the SharePoint estate. GA expected September 2026; start planning your skill governance approach now.
Microsoft Teams: Enable agents for existing applications in your organization [GA] - Admins can now discover and enable Teams agents for third-party apps already deployed in the tenant directly from the Teams Admin Center, with guidance on required configuration changes. GA expected October 2026; review your existing app portfolio for agent-eligible applications.
Microsoft Teams: App centric management in Teams Admin Center to manage the Apps access for tenants, end-users, and groups in DoD [GA] - App centric management replaces app permission policies for DoD tenants, letting admins set per-app availability to all users, specific users/groups, or no users. GA expected for DoD; validate that your existing permission policies translate correctly during migration.
Microsoft Teams: App centric management in Teams Admin Center to manage the Apps access for tenants, end-users, and groups in GCC High [GA] - The same app centric management capability arrives for GCC High, replacing app permission policies with per-app install controls. Existing policies are migrated automatically, but verify the resulting availability settings match your intended posture post-migration.
Microsoft Teams: Badges in Profile Card in Teams [GA] - Awards and Certifications from Viva now surface as badges on Teams and Outlook profile cards, providing a consistent cross-surface experience. GA expected October 2026; no admin action required, but consider communicating this to HR and learning teams.
Microsoft Teams: Unified Agent and App Installation Management Across Microsoft 365 and Teams Admin Center [GA] - App and agent installation changes made in either the M365 admin center or Teams admin center now propagate consistently across Teams, Outlook, and Microsoft 365 Copilot. This closes the longstanding split where M365 admin center changes didn’t affect Teams and vice versa. GA August 2026; audit your current admin center settings in both portals to confirm they align.
Microsoft Teams: AI-generated meeting archive for knowledge retention [GA] - Admins can enable a tenant-wide policy allowing Copilot to retain key meeting insights beyond transcript retention periods, with configurable storage duration. GA expected October 2026; this has data retention and governance implications, so align with your records management and legal teams before enabling.
Microsoft Edge: Auto-open Copilot side pane for Outlook links [GA] - When users open links from Outlook in Edge, the Copilot side pane can automatically open with contextual insights based on email and destination content. Admins control this via the
M365LinksAutoOpenCopilotEnabledpolicy. GA expected October 2026; decide whether this default-on behavior fits your user experience and data governance expectations before it rolls out.
AI & Copilot
An AI Agent Builds Another Agent [GA] - Demonstration of an agent using the GitHub CLI with Work IQ to scaffold and deploy a new Copilot agent from a Teams conversation. Relevant for teams building agent-based automation; illustrates the MCP server and plugin composition model in practice.
API vs MCP Connectors for Copilot [GA] - API connectors index data for read operations; MCP servers support both read and write and aren’t indexed. Both are configured under Copilot Connectors in the M365 admin center. If you’re extending Work IQ to line-of-business systems, understanding this distinction is prerequisite to designing the right connector architecture.
When AI infrastructure becomes the target: Securing gateways and control points [GA] - Microsoft Threat Intelligence documents active attacks against exposed AI workloads, specifically LiteLLM gateway exploitation leading to credential harvesting, persistence, and cryptomining. If your organization runs self-hosted AI gateway infrastructure, review exposure, authentication controls, and network segmentation now.
One always-on roadmap: Dynamics 365, Power Platform, and Dataverse join the AI at Work roadmap [GA] - Dynamics 365, Power Platform, and Dataverse feature planning now flows through the AI at Work roadmap rather than the twice-yearly release wave model. If you track Power Platform changes for governance or change management purposes, update your roadmap monitoring processes to point at the new destination.
Copilot Cowork Runs Your Whole Workflow [GA] - Copilot Cowork can generate a briefing doc, presentation, and spreadsheet from a single prompt while accepting new tasks in parallel. This multi-output, concurrent execution model is relevant for understanding how Copilot’s agent capabilities will reshape user expectations around task automation.
Microsoft Agent 365: the control plane for agents [GA] - Agent 365 is now GA as the centralized control plane for observing, governing, and securing AI agents across Microsoft 365 and connected platforms. If you don’t yet have an agent governance practice, this is where it starts; review what agents are active in your tenant and set baseline policies.
Security & Compliance
Close the gaps: layered data protection with Microsoft Purview across endpoint, browser, and network [GA] - Purview DLP coverage across endpoint, browser (Edge), and network layers is positioned as complementary enforcement, each layer covering what the others can’t. If you have gaps in your DLP posture, this post provides a useful framework for identifying which layer addresses which scenario, especially relevant as AI tools accelerate data movement.
Introducing Multi-Account Support for Connectors in Microsoft Sentinel [GA] - Sentinel data connectors for Auth0, CrowdStrike Falcon, and Salesforce Service Cloud now support multi-account ingestion from a single connector configuration. If your estate includes multiple CrowdStrike tenants or Salesforce orgs, consolidate your connector configurations to reduce operational overhead and close visibility gaps.
One SOC, Many Tenants: Centralizing Microsoft Sentinel with Azure Lighthouse [GA] - Azure Lighthouse enables a central SOC hub to operate across multiple Entra ID tenants with scoped delegated access, without log centralization and the compliance risk that brings. If you manage a multi-tenant environment from a single SOC and haven’t evaluated Lighthouse for Sentinel, this is the reference architecture to start from.
Sensor v2.x installation restriction for new Defender for Identity workspaces [GA] - New Defender for Identity workspaces can only install sensor v2.x on servers running Windows Server 2016 or earlier. Servers running 2019 or later in new workspaces require a different deployment method. Existing workspaces are unaffected; this only impacts net-new deployments.
TerminalFix campaign deploys a reverse tunnel through multistage intrusion [GA] - Active ClickFix-style campaign using fake CAPTCHA prompts, DLL sideloading, and reverse tunnel establishment. Microsoft Threat Intelligence includes detection guidance and hunting queries. Run the provided hunting queries in Defender XDR or Sentinel against your environment, and verify DLL sideloading protections are in place on endpoints.
Action Required
CVE-2026-62823 - Windows DHCP Server Remote Code Execution - Critical · CVSS 8.8 - Surfaced in the Week of 2026-09-01 digest. A Critical-severity RCE in the Windows DHCP Server service; network-adjacent attackers could exploit this without authentication. Verify all Windows Server DHCP roles are patched across your estate immediately.
CVE-2026-62889 - Windows SSTP Remote Code Execution - Critical · CVSS 8.1 - Surfaced in the Week of 2026-09-01 digest. Critical RCE in the Secure Socket Tunneling Protocol stack on Windows Server; if you’re running SSTP-based VPN endpoints, apply this patch before your next maintenance window and consider temporary exposure reduction if patching is delayed.
CVE-2026-65775 - Windows Win32k Elevation of Privilege - Important · CVSS 7.8 - Surfaced in the Week of 2026-09-01 digest. EoP in Win32k; acknowledgment-only update this cycle, patch was previously released. Confirm deployed.
CVE-2026-65776 - Windows Win32k Elevation of Privilege - Important · CVSS 7.0 - Surfaced in the Week of 2026-09-01 digest. Second Win32k EoP this week; acknowledgment update, verify prior patch is applied.
CVE-2026-55134 - Microsoft Word Remote Code Execution - Important · CVSS 7.8 - Surfaced in the Week of 2026-09-01 digest. RCE in Word via crafted documents; acknowledgment update, confirm patch is deployed across managed Office clients.
CVE-2026-50448 - Windows NTFS Remote Code Execution - Important · CVSS 7.8 - Surfaced in the Week of 2026-09-01 digest. RCE in the NTFS driver; acknowledgment update, verify prior patch coverage.
CVE-2026-50344 - Windows OLE Elevation of Privilege - Important · CVSS 7.8 - Surfaced in the Week of 2026-09-01 digest. EoP via Windows OLE; acknowledgment update, confirm patch is applied.
CVE-2026-50462 - Windows Ancillary Function Driver for WinSock Elevation of Privilege - Important · CVSS 7.8 - Surfaced in the Week of 2026-09-01 digest. EoP in the WinSock AFD driver; acknowledgment update, verify patch deployment.
CVE-2026-59134 - Remote Desktop Client Remote Code Execution - Important · CVSS 7.5 - Surfaced in the Week of 2026-09-01 digest. RCE in the Remote Desktop Client; acknowledgment update, confirm patch is applied to client devices.
CVE-2026-68821 - Windows Package Manager Elevation of Privilege - Important · CVSS 7.3 - Surfaced in the Week of 2026-09-01 digest. EoP in Windows Package Manager (winget); security update link information was revised, verify the correct patch is deployed.
CVE-2026-26174 - Windows Server Update Service (WSUS) Elevation of Privilege - Important · CVSS 7.0 - Surfaced in the Week of 2026-09-01 digest. EoP in WSUS; acknowledgment update, confirm patch is applied to any WSUS infrastructure still in use.
CVE-2026-64899 - Microsoft Office Information Disclosure - Important · CVSS 5.5 - Surfaced in the Week of 2026-09-01 digest. Information disclosure in Office; acknowledgment-only update, patch was previously released. Confirm applied.
CVE-2026-49177 - Windows TCP/IP Information Disclosure - Important · CVSS 5.5 - Surfaced in the Week of 2026-09-01 digest. Information disclosure in the Windows TCP/IP stack; acknowledgment update, verify prior patch is deployed.
CVE-2026-70331 - Microsoft Edge for iOS Spoofing - Moderate · CVSS 5.4 - Surfaced in the Week of 2026-09-01 digest. Spoofing via improper neutralization of LLM prompt input in Edge for iOS; ensure managed iOS devices have the latest Edge version deployed via Intune MAM/MDM policies.
CVE-2026-58616 - Copilot Chat (Microsoft Edge) Information Disclosure - Moderate · CVSS 4.4 - Surfaced in the Week of 2026-09-01 digest. Race condition in Copilot Chat within Edge can allow an authorized attacker to disclose information over a network; update Edge to the latest version across managed devices.
Exchange Online identifier deprecation survey - No hard deadline published yet, but the Exchange team is actively making decisions. Audit all automation, scripts, connectors, and third-party integrations that reference ObjectGuid, SamAccountName, or DistinguishedName for Exchange objects, then submit your use cases via the survey to influence the outcome.
Upcoming changes to classic experiences in SharePoint Online - Timelines are published in the accompanying Learn article. Inventory any sites still using classic publishing pages, classic master pages, or classic web parts, and begin migration planning to the modern SharePoint framework.
Defender for Identity sensor v2.x restriction for new workspaces - Effective now for new workspaces. If you’re deploying a new Defender for Identity workspace and have servers running Windows Server 2019 or later, plan your sensor deployment method accordingly before provisioning the workspace.
Microsoft Teams AI-generated meeting archive - GA expected October 2026. Review data retention, records management, and legal hold implications before this policy option becomes available; align with your legal and compliance teams on whether to enable it and at what retention duration.
Documentation Updates
Endpoint & Device Management
Windows Autopilot device association documentation published - New reference documentation for the GA Autopilot device association feature, including the deployment workflow and how hardware-backed attestation integrates with device preparation.
Device association export timeout troubleshooting added - New troubleshooting guidance covering export timeout errors in the device association workflow, relevant if you encounter failures during bulk device registration.
Intune network endpoints updated with new Azure Front Door IPs - The Intune required endpoints list now includes updated Azure Front Door IP ranges; review against firewall and proxy allowlists to avoid connectivity issues for managed devices.
MFA limitation removed from Android web enrollment docs - A previously documented MFA limitation for Android web enrollment has been removed, indicating this restriction no longer applies. Revisit any enrollment guidance or user communications you had in place based on the old constraint.
Windows 365 for Agents baseline settings reference published - New baseline configuration settings reference specifically for Windows 365 for Agents, covering the recommended security and management configuration for agent-hosted Cloud PCs.
Microsoft Tunnel 2608 release documentation updated - Updated documentation for the 2608 Microsoft Tunnel server release; review for any configuration or compatibility changes before updating Tunnel server infrastructure.
Identity & Access
Microsoft-managed TLS certificate configuration guidance added - New documentation covering how Microsoft-managed TLS certificates work in Entra, relevant for teams configuring custom domains or application proxy scenarios where certificate lifecycle management matters.
Self-service SCIM provisioning validation docs for Entra App Gallery - New documentation for the self-service SCIM provisioning validation process for apps targeting the Microsoft Entra App Gallery, providing the requirements and steps for ISVs and partners integrating provisioning support.
Sources
- https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-august/ba-p/4537393
- https://techcommunity.microsoft.com/t5/intune-customer-success/introducing-device-association-for-windows-autopilot-device/ba-p/4550603
- https://techcommunity.microsoft.com/t5/intune-customer-success/remote-help-on-windows-unattended-support-with-remote-sign-in-is/ba-p/4549772
- https://azure.microsoft.com/en-us/blog/the-patch-window-is-collapsing-why-security-needs-a-new-control-plane/
- https://techcommunity.microsoft.com/t5/microsoft-purview-blog/close-the-gaps-layered-data-protection-with-microsoft-purview/ba-p/4550997
- https://techcommunity.microsoft.com/t5/microsoft-security-community/introducing-multi-account-support-for-connectors-in-microsoft/ba-p/4546440
- https://techcommunity.microsoft.com/t5/microsoft-security-community/one-soc-many-tenants-centralizing-microsoft-sentinel-with-azure/ba-p/4543629
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64899
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65775
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65776
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62889
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59134
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49177
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55134
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50448
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50344
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50462
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26174
- https://learn.microsoft.com/en-us/defender-for-identity/deploy/deploy-defender-identity#select-your-deployment-method
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68821
- https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70331
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58616
- https://techcommunity.microsoft.com/t5/microsoft-entra-blog/instant-revocation-of-service-principal-bearer-tokens-with-cae/ba-p/4548192
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/upcoming-changes-to-classic-experiences-in-sharepoint-online/ba-p/4549091
- https://www.youtube.com/shorts/k9akHVZeU1A
- https://techcommunity.microsoft.com/t5/exchange-team-blog/tell-us-how-you-use-objectguid-samaccountname-and/ba-p/4550939
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/sharepoint-showcase-5-ways-organizations-improve-business/ba-p/4549704
- https://www.youtube.com/shorts/KMuaehDm_jE
- https://www.youtube.com/shorts/B9jID_ycpBE
- https://techcommunity.microsoft.com/t5/microsoft-sharepoint-blog/streamlining-enterprise-collaboration-acp-sharepoint-partner/ba-p/4550384
- https://techcommunity.microsoft.com/t5/microsoft-teams-blog/turn-conversations-into-code-with-github-copilot-in-microsoft/ba-p/4548305
- https://www.microsoft.com/microsoft-365/roadmap?id=570155
- https://www.microsoft.com/microsoft-365/roadmap?id=569608
- https://www.microsoft.com/microsoft-365/roadmap?id=569434
- https://www.microsoft.com/microsoft-365/roadmap?id=569433
- https://www.microsoft.com/microsoft-365/roadmap?id=568078
- https://www.microsoft.com/microsoft-365/roadmap?id=567883
- https://www.microsoft.com/microsoft-365/roadmap?id=558933
- https://www.microsoft.com/microsoft-365/roadmap?id=557561
- https://www.youtube.com/shorts/2hfhZPEgjFw
- https://www.youtube.com/shorts/iTjbEQHuUrY
- https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points/
- https://www.microsoft.com/en-us/dynamics-365/blog/business-leader/2026/08/25/one-always-on-roadmap-dynamics-365-power-platform-and-dataverse-join-the-ai-at-work-roadmap/
- https://www.youtube.com/shorts/pg5j3QzH8P0
- https://www.microsoft.com/microsoft-365/roadmap?id=558448
