Top 5

  1. CVE-2026-85921 - Critical Windows Secure Kernel EoP: A double-free in Windows Secure Kernel Mode allows local privilege escalation with a CVSS of 8.2. Patch this immediately across your Windows Server and endpoint fleet before any PoC surface. Critical severity with no reported exploitation yet, but local EoP in the secure kernel is a high-value primitive for post-compromise chains.

  2. Agent 365 GA for cross-vendor AI governance: Microsoft’s Agent 365 gives admins a single registry to track, approve, and lock down AI agents from Microsoft, Amazon, Google, Salesforce, Databricks, and Anthropic. Shadow AI blocking via Intune policies and Execution Container isolation is available now. If your organization is running or planning to run third-party agents, this is the governance layer to evaluate this week.

  3. September 2026 Exchange Server Security Updates released: Security updates are out for Exchange SE, 2019, and 2016. Exchange 2019 CU14/CU15 and 2016 CU23 require Period 2 ESU enrollment to access. If you run on-premises Exchange, apply these immediately and confirm your ESU enrollment status before attempting to download.

  4. Passkey-themed social engineering actively abusing Microsoft Graph: A documented attack chain uses passkey-themed lures to establish MFA persistence, then pivots through Microsoft Graph to reach SharePoint, OneDrive, and email. Review your Conditional Access policies and Graph API access controls now, particularly for any app with broad Mail.Read or Files.Read.All delegated permissions.

  5. NTLM retirement FAQ published, slmgr.vbs deprecation in motion: Microsoft has published a formal NTLM retirement FAQ covering the Kerberos-first, NTLM-optional path. Separately, slmgr.vbs is on its way out with VBScript removal. Both are medium-term breaking changes: audit NTLM dependencies in your environment and inventory any activation automation that calls slmgr.vbs.

Identity & Access

  • Combined Sensor management tab in Defender for Identity on-premises settings [GA] - The Onboarding and Sensors tabs are now merged into a single Sensor management tab that shows both installed sensors and servers eligible for activation; automatic sensor v3.x activation has moved to the Advanced features page. If you manage Defender for Identity sensor deployments, update your runbooks and any documentation that references the old tab layout.

  • Passkey-themed social engineering leading to identity and cloud compromise [GA] - Threat actors are using passkey-themed lures to establish MFA persistence, then abusing Microsoft Graph for reconnaissance and accessing SharePoint, OneDrive, and email data. Review Conditional Access policies, audit delegated Graph API permissions, and check for suspicious MFA method registrations in your Entra ID sign-in and audit logs immediately.

Endpoint & Device Management

  • Defender for Identity sensor v3.x onboarding without Defender for Endpoint (Preview) [Preview] - You can now activate the Defender for Identity sensor v3.x on eligible domain controllers running Windows Server 2019 or later without first onboarding those DCs to Defender for Endpoint. This removes a significant blocker for organizations that want identity telemetry on DCs before full MDE deployment is complete; evaluate this for your staged rollout plans.

  • Migrate Windows activation automation from slmgr.vbs to PowerShell [GA] - VBScript deprecation means any automation relying on slmgr.vbs will eventually break when VBScript is removed from Windows. The OSLicense PowerShell module is now the recommended replacement; start inventorying activation scripts now and build migration into your next change window.

  • Run local AI models on a Windows 365 Cloud PC with Foundry Local [GA] - Windows 365 Cloud PCs can run small language models (Qwen, Phi) locally via Foundry Local, letting AI-assisted workloads run on the Cloud PC’s own storage without consuming cloud AI tokens. This is worth evaluating for developer or analyst Cloud PC SKUs where token costs are a concern.

  • NTLM retirement FAQ: Planning your path to Kerberos-first [GA] - Microsoft has published a comprehensive FAQ covering the transition to Kerberos-first, NTLM-optional, and eventually NTLM-free Windows environments. Use this as the reference document when building your NTLM dependency audit and remediation plan; NTLM is still present in most environments as a fallback that few teams have formally inventoried.

  • Copilot entry point coming to Classic Outlook for Windows [GA] - The unified Copilot entry point already shipping in new Outlook, Word, Excel, and PowerPoint is rolling out to Classic Outlook this September. No admin action required, but expect user questions about the new UI anchor point if Classic Outlook is your standard deployment.

Collaboration & Productivity

  • AI-assisted BEC campaign using executive impersonation and invoice fraud [GA] - Microsoft has documented an active business email compromise campaign using AI-generated executive impersonation to target finance teams with fake ACH payment requests. Brief your finance and AP teams, validate your Defender for Office 365 impersonation protection policies, and confirm that payment-change requests require out-of-band verification.

  • SharePoint AI page authoring: on-canvas selection for Copilot edits [GA] - Authors can now select a specific section or web part on a SharePoint page and instruct Copilot to modify it directly, removing the need to describe the element’s location in natural language. No admin configuration required; the capability is rolling out to licensed Copilot users with SharePoint authoring rights.

  • Field guide: Testing EWSAllowedAppIDs before enforcing EWS retirement controls [GA] - As EWS retirement in Exchange Online approaches its final phase, the Exchange team has published a controlled positive/negative test methodology for validating EWSAllowedAppIDs, including a warning about a commonly confused similarly named control that operates at a different layer. Run this validation in a test tenant or pilot group before enforcing the allowlist in production.

  • September 2026 Exchange Server Security Updates [GA] - Security updates are released for Exchange SE RTM, Exchange 2019 CU14/CU15, and Exchange 2016 CU23; access to 2019 and 2016 updates requires Period 2 ESU enrollment. Apply these patches immediately on all on-premises Exchange servers and verify ESU enrollment status before attempting to retrieve the update packages.

  • Exchange Server AD FS Modern Authentication now extends to Outlook for iOS and Android [GA] - Pure on-premises Exchange organizations using AD FS Modern Authentication can now extend that auth path to Outlook for iOS and Outlook for Android, completing mobile client coverage alongside the existing Windows, Mac, and native iOS/macOS Mail support. If your organization maintains a pure on-premises Exchange deployment with AD FS, test and deploy the updated Outlook mobile configuration to eliminate legacy auth fallback on mobile.

  • Queues app for Teams: Collaborative calling for customer-facing teams [GA] - The Queues app turns a Teams call queue into a shared workspace where agents and supervisors manage customer calls together inside Teams, with recent updates expanding supervisor controls and queue visibility. Requires Teams Phone and is suited for branch banking, IT help desks, and any team handling inbound calls alongside regular Teams collaboration.

  • Microsoft Teams: Report suspicious guest invitations coming in November 2026 [GA] - Users will be able to flag unexpected or potentially malicious guest invitations directly from Teams for IT admin review, adding a human reporting signal to your guest access monitoring. No admin action required before GA, but plan to communicate the feature to users and establish a review workflow for flagged invitations.

  • Outlook Cloud Policy controls coming to Outlook on the web and new Outlook for Windows [GA] - Cloud Policy service support for Outlook on the web and new Outlook for Windows will let admins set and lock default Outlook settings across the organization via a cloud-based policy plane. Arriving October 2026; start identifying settings you currently enforce via Group Policy or registry that should migrate to Cloud Policy for cloud-managed users.

  • Teams Panels: Admin control to hide organizer name in Calendar View [GA] - Admins can toggle the “Show organizer name” setting on or off in the Pro Management portal or directly on the panel device, enabling privacy control for sensitive meeting organizer information on room displays. Requires Teams Rooms Pro or Teams Shared Space license; GA in October 2026.

  • Planner integration coming to Microsoft Cowork [GA] - Cowork will allow users to view, create, and update Planner plans, buckets, goals, and tasks without leaving the app, and can execute Planner tasks across M365 (send emails, schedule meetings, post Teams updates) before writing progress back to Planner with user approval. GA October 2026; no admin action required, but this changes the primary surface where some users will interact with Planner.

  • Copilot Settings now in Classic Outlook for Windows (Preview) [Preview] - Classic Outlook for Windows is gaining direct access to Copilot settings within the app itself, matching the settings access already available in other Outlook endpoints. Preview available since July 2026; no admin configuration required.

  • Exchange Online Cross-tenant Message Recall now GA [GA] - Exchange Online Message Recall now supports recalling messages sent to external organizations, provided the recipient tenant has added your tenant to their recall allow list. Coordinate with key partner organizations to establish mutual allow-list entries if cross-tenant recall is operationally important for your compliance posture.

AI & Copilot

  • Block shadow AI on managed devices with Agent 365 [GA] - Agent 365 lets admins configure default blocks for unsanctioned local AI agents, enforced through underlying Intune policies, and mandates that any permitted local agent runs isolated from the primary user session via Microsoft Execution Containers. If shadow AI governance is on your roadmap, this is the concrete enforcement mechanism now available.

  • Agent 365: Cross-vendor AI agent registry and governance controls for admins [GA] - Agent 365 provides a unified registry covering agents from Microsoft, Amazon, Google, Salesforce, Databricks, Anthropic, and others, with reusable security policy templates that apply Conditional Access, Access Packages, and Custom Security Attributes at the point of agent approval. This is the broadest AI governance surface Microsoft has shipped; evaluate it against your AI risk and procurement policies now.

  • Copilot Notebooks redesigned in Microsoft 365 Copilot app for iOS [GA] - Copilot Notebooks on iOS now let users collect related chats, outputs, and references into a persistent AI workspace that carries context across sessions, so users are not starting from scratch on each interaction. GA September 2026; no admin configuration required, but users with heavy Copilot usage should be made aware of the organizational capability.

  • Custom engine agents now available for GCC-M users [GA] - GCC-M tenants can now use custom engine agents within Microsoft 365 Copilot extensibility, closing a gap between commercial and sovereign cloud feature parity. If you manage a GCC-M environment and have custom agent development underway, validate deployment now that the feature is live.

Security & Compliance

  • Chromium CVE-2026-87494: Use after free in Browser [GA] - Severity: not yet rated by MSRC. A use-after-free in the Chromium browser engine is addressed in the latest Edge update; ensure managed Edge deployments are on the current channel version.

  • Chromium CVE-2026-87493: Missing authorization in FileSystem [GA] - Severity: not yet rated by MSRC. A missing authorization flaw in Chromium’s FileSystem component is patched in the current Edge release; verify Edge is current across your managed device fleet.

  • Chromium CVE-2026-87492: Incorrect authorization in DevTools [GA] - Severity: not yet rated by MSRC. An incorrect authorization issue in Chromium DevTools is addressed in the latest Edge channel update; confirm DevTools access restrictions align with your security baseline.

  • Chromium CVE-2026-87490: Information leak in Transactions Platform [GA] - Severity: not yet rated by MSRC. An information leak in the Chromium Transactions Platform component is patched in the current Edge release; keep managed Edge deployments current.

  • Chromium CVE-2026-87489: Memory corruption in V8 [GA] - Severity: not yet rated by MSRC. Memory corruption in the V8 JavaScript engine is addressed in the latest Edge update; V8 memory corruption bugs carry elevated exploitation risk and Edge should be prioritized for update.

  • Chromium CVE-2026-87487: Missing authorization in FileSystem [GA] - Severity: not yet rated by MSRC. A second missing authorization flaw in Chromium’s FileSystem component is patched alongside CVE-2026-87493 in the current Edge channel; ensure Edge is updated across all endpoints.

  • Chromium CVE-2026-87485: Incorrect authorization in CORS [GA] - Severity: not yet rated by MSRC. An incorrect authorization issue in Chromium’s CORS implementation is addressed in the current Edge release; update managed Edge to the latest build.

  • Chromium CVE-2026-87484: UI misrepresentation in Geometry [GA] - Severity: not yet rated by MSRC. A UI misrepresentation flaw in Chromium’s Geometry component is patched in the current Edge update; ensure Edge is current on managed devices.

  • Chromium CVE-2026-87480: Use after free in Printing [GA] - Severity: not yet rated by MSRC. A use-after-free in the Chromium Printing component is addressed in the latest Edge channel release; keep Edge updated across your managed fleet.

  • Chromium CVE-2026-87458: UI misrepresentation in Geometry [GA] - Severity: not yet rated by MSRC. A second UI misrepresentation flaw in Chromium’s Geometry component is patched in the current Edge release alongside CVE-2026-87484; update Edge to the latest build.

  • Chromium CVE-2026-87457: Race condition in Updater [GA] - Severity: not yet rated by MSRC. A race condition in the Chromium Updater component is addressed in the current Edge update; confirm managed Edge deployments are on the latest channel version.

  • Chromium CVE-2026-87456: Uninitialized resource in Media [GA] - Severity: not yet rated by MSRC. An uninitialized resource flaw in the Chromium Media component is patched in the latest Edge release; ensure Edge is updated on all managed endpoints.

  • Chromium CVE-2026-87455: Use after free in Aura [GA] - Severity: not yet rated by MSRC. A use-after-free in the Chromium Aura window management layer is addressed in the current Edge channel; update managed Edge to the latest build.

  • Chromium CVE-2026-87454: Information leak in Enterprise [GA] - Severity: not yet rated by MSRC. An information leak in Chromium’s Enterprise component is patched in the current Edge release; this is particularly relevant for organizations using enterprise browser policies and should be addressed promptly.

  • CVE-2026-85921: Critical Windows Secure Kernel Mode Elevation of Privilege [GA] - Critical · CVSS 8.2. A double-free vulnerability in Windows Secure Kernel Mode allows a local authorized attacker to elevate privileges. Patch all affected Windows systems immediately; local EoP in the secure kernel is a high-value primitive in post-compromise attack chains.

  • Detect and disrupt AI-themed attacks with Microsoft Defender [GA] - Microsoft Defender’s detection and disruption capabilities for AI-themed phishing, malware, and multi-stage attacks are documented here with attack chain coverage. Review your Defender XDR incident response playbooks to ensure AI-lure campaigns are addressed in your detection scenarios.

  • Cloud Web Applications Threat Matrix: MITRE ATT&CK-aligned framework [GA] - Microsoft has released a new threat matrix covering cloud-hosted web apps and serverless platforms, aligned to MITRE ATT&CK, to help defenders prioritize and mitigate relevant threat vectors. Use this to update your threat model if your organization hosts web applications or serverless workloads in Azure or hybrid environments.

  • Azure AI Foundry: Synthetic test data generation for agent evaluation [GA] - Azure AI Foundry can generate synthetic evaluation datasets from a natural-language prompt, eliminating the cold-start problem for teams building AI agent evaluation pipelines without existing labeled data. Useful for any team building or evaluating Copilot Studio agents or custom engine agents that need a structured test harness.

  • Microsoft Foundry Toolbox: 90% token reduction through targeted tool routing [GA] - The Toolbox feature in Microsoft Foundry routes each agent request to only the tools it actually needs rather than broadcasting all tool definitions on every call, cutting one sample run from roughly 4,700 to 467 input tokens with equivalent output quality. If your team is managing agent token costs at scale, evaluate Toolbox routing as an immediate optimization.

  • OneDrive mobile: PDF annotation for sensitivity-label protected files on iOS and Android [GA] - The OneDrive apps for iOS and Android now allow users with edit/annotate rights to add ink, highlights, free text, notes, signatures, stamps, bookmarks, and form fields to sensitivity-label encrypted PDFs without removing or downgrading the label. This closes a workflow gap for mobile workers handling protected documents; verify your Information Protection label configurations grant the appropriate usage rights to users who need annotation access.

Action Required

Documentation Updates

Identity & Access