Top 5

  1. CVE-2026-78510 Critical Outlook and Word RCE on Mac, CVSS 9.8: A network-exploitable remote code execution vulnerability in Microsoft Outlook and Word for Mac carries the highest-severity CVSS score in this week’s batch. Users running affected Mac Office software need the security update applied immediately; no user interaction is required for exploitation at this score level. Check your Mac fleet patch status now and verify the update is deployed before end of week.

  2. Agent 365 unified registry now governs cross-platform AI agents: Microsoft Agent 365’s unified registry is GA and can now pull in agents from AWS Bedrock, Google Cloud, Databricks, Anthropic, and Salesforce alongside all Microsoft-native agents. This is the practical answer to the question of how many AI agents are actually running in your tenant: connect your external platforms via API or service domain, and they surface with owner, usage, and risk data attached. If you haven’t started your agent inventory, this week is the trigger.

  3. Intune deployment plans GA for staged app and policy rollout: Staged rollouts for apps and configuration policies are now available natively in Intune, with ring-based sequencing, timing controls, and Multiple Admin Approval integration. For large device fleets this replaces improvised rollout processes built on dynamic groups and manual sequencing. Start evaluating the Deployments experience in the admin center for your next major policy push.

  4. Six AI-Readiness Secure Score recommendations now GA in Defender: Defender for Endpoint has added six new Secure Score recommendations specifically targeting endpoint hardening against AI-accelerated attacks, covering external attack surface reduction, hardware-backed boot trust, VBS, kernel code integrity, and local admin credential reuse. Pull your current Secure Score and triage these recommendations against your existing hardening baselines this sprint.

  5. Autopilot device preparation: migration guidance now published: Microsoft has published the official migration guide from classic Windows Autopilot to Autopilot device preparation, which re-architects provisioning around simpler configuration, faster setup, and near-real-time deployment reporting. If you have mature Autopilot profiles, ESP settings, group tags, and dynamic groups, read this before you start planning the migration timeline. The architectural differences are substantial enough that a lift-and-shift approach will not work.


Identity & Access

  • Prepare your tenant estate for AI: Entra Tenant Governance webinars [GA] - Entra Tenant Governance is now GA and gives you visibility and consistent policy enforcement across every tenant in your estate, including shadow tenants from M&A and test environments. Microsoft is running webinars to walk through deployment; if multi-tenant sprawl is a known risk in your environment, this is worth booking. Register before spots fill.

  • Public preview: Self-service onboarding for Entra App Gallery [Preview] - ISVs can now validate and publish new App Gallery integrations through a guided self-service workflow instead of iterative review cycles with Microsoft. For admins, this means faster time-to-availability for new SaaS apps in the gallery. No action required now, but expect the catalog to grow more quickly going forward.

  • Replace VPN with Entra Private Access, identity-driven per-app connectivity [GA] - Entra Private Access within the Global Secure Access framework is GA and provides per-app, identity-driven connectivity to private resources as a direct VPN replacement. The post clarifies the architecture clearly: Global Secure Access is the broader SSE framework; Entra Private Access is the VPN-replacement component. If your Zero Trust roadmap still has VPN retirement as a future item, this is the implementation path.


Endpoint & Device Management

  • Stage app and policy rollout with deployment plans [GA] - Intune now supports native deployment plans for staged rollout of apps and configuration policies across rings, with timing controls and Multiple Admin Approval integration. This directly addresses the risk of broad policy pushes to large fleets going wrong with no rollback gate. Explore the new Deployments experience in the Intune admin center and consider adopting it for your next major configuration change.

  • Windows 365 Reserve: User-initiated provisioning now GA [GA] - Eligible users can now provision their own Reserve Cloud PC directly from Windows App when their primary device fails, operating within IT-defined policy boundaries. This reduces help desk load during device outage events without giving users unconstrained provisioning rights. Review your Windows 365 Reserve license assignments and decide whether to enable this for your user population.

  • Moving from Windows Autopilot to Windows Autopilot device preparation [GA] - Microsoft has published a detailed migration guide for organizations moving from classic Autopilot to the re-architected Autopilot device preparation experience, which delivers simpler configuration, faster provisioning, and near-real-time deployment reporting. The architectural shift is significant: existing profiles, ESP settings, group tags, and dynamic groups do not map directly. Read the migration guide before scheduling any tenant transition work.

  • Ask the Windows 365 admin agent why Cloud PCs are slow [GA] - The Windows 365 admin agent can now analyze Cloud PC connectivity device by device, identify where RDP Shortpath is not in use, and recommend configuration changes to improve performance. If you’re regularly triaging Cloud PC performance complaints, this agent capability can significantly reduce investigation time. Check the Windows 365 admin center to verify agent access is configured for your admin accounts.


Collaboration & Productivity

  • CVE-2026-78510 Microsoft Outlook and Word RCE on Mac, CVSS 9.8 [GA] - Critical · CVSS 9.8. A network-exploitable remote code execution vulnerability in Office for Mac affects both Outlook and Word. Apply the Mac Office security update immediately across your managed Mac fleet; users on unmanaged Macs need direct notification. This is the highest-severity CVE in this week’s digest.

  • Queues app for Teams: Collaborative calling now GA [GA] - The Queues app turns Teams call queues into a shared workspace where calling reps and supervisors work the same customer conversations together inside Teams. This targets bank branches, IT help desks, and similar teams handling customer calls alongside other work. If your organization runs call queues in Teams, evaluate Queues app as a replacement for standalone contact center tooling.

  • Microsoft Teams: Granular Conditional Access for Teams meetings [GA] - Admins will be able to apply Conditional Access policies to individual meetings, enforcing organizational security requirements before participants can join. GA target is November 2026. Start identifying which meeting types (executive briefings, board meetings, sensitive project reviews) would benefit from meeting-level CA policies.

  • Dynamics 365 Customer Service: Inactivate quality evaluation records [GA] - Quality managers can now inactivate evaluation records that should not contribute to scoring, preserving them for audit purposes while excluding them from active score calculations. GA target is September 2026. Useful for correcting results from duplicate, misconfigured, or incorrectly scoped evaluations.

  • Dynamics 365 Customer Service: Detailed quality evaluation score breakdown [GA] - Evaluation details now show scoring at the overall, section, and question level so quality teams can see exactly how scores are composed and identify where coaching or calibration is needed. GA target is September 2026.

  • Microsoft Teams: Events app coming to GCC High and DoD [GA] - The Meet app is being renamed to Events app and will be available in GCC High and DoD tenants, allowing users to discover, plan, and organize professional events from within Teams. GA target is November 2026. GCC High and DoD admins should review any existing Meet app policies ahead of the rename.

  • Microsoft Teams: Pop out sign language interpreter video for continuous visibility [GA] - Users can pop out any participant’s video, including sign language interpreters, into a persistent, resizable window that stays visible across monitors and apps during meetings. GA target is December 2026. This addresses a real accessibility gap for Deaf and Hard of Hearing participants who lose interpreter visibility when sharing content or switching layouts.

  • Microsoft Teams: Express face enrollment [GA] - Users can enroll their face profile during eligible meetings using their camera, enabling recognition in Teams Rooms experiences for improved Copilot and recap features. Admins can enable or disable this for their org. GA target is November 2026. Review your biometric data policies before this feature lands and decide on your default stance.

  • Microsoft Teams: Report a Security Concern in Meetings [GA] - Meeting organizers and attendees can now report suspicious or potentially fraudulent activity directly from within Teams meetings, with reports flowing into Microsoft security and admin workflows. GA target is September 2026. Confirm your user-reported settings and reporting mailbox configuration in the Teams admin center to ensure reports land in the right place.

  • Microsoft Teams: Identify custom apps needing updates for private and shared channels [GA] - Teams Admin Center will surface a list of custom apps that need developer updates to work in private and shared channels. GA target is September 2026. Run this report as soon as it’s available and engage app owners for any business-critical custom apps that appear on the list.

  • Microsoft Teams Admin Center: Single pane for meeting and call monitoring [GA] - Admins can now monitor meeting and call health, identify recurring patterns, and proactively troubleshoot issues across both active and completed sessions from a single view in Teams Admin Center. GA target is September 2026. This consolidates what previously required navigating multiple reporting surfaces and should reduce mean time to diagnose call quality issues.


AI & Copilot

  • Power Pages: Invoke Power Automate cloud flows from Server Logic [GA] - Server Logic in Power Pages can now call Power Automate cloud flows directly, letting portal experiences participate in broader enterprise automation without custom code. This extends what you can build in Power Pages without requiring server-side customization work. Review your existing Power Pages implementations to identify processes that could be offloaded to cloud flows.

  • Power Platform: September 2026 feature update [GA] - The September update includes Power Series, a set of 20 hands-on labs from the Power CAT team covering Power Platform and AI skills, now available for customers, partners, and field teams. Worth distributing to your maker community and anyone building with AI in Power Platform.

  • Power Pages: Microsoft-managed SSL/TLS certificates for custom domains [GA] - Microsoft now provisions, configures, and renews SSL/TLS certificates automatically for custom domains on Power Pages. This eliminates certificate expiry risk for portals using custom domains. If you manage Power Pages sites with manually tracked certificates, migrate to the managed option to remove that operational overhead.

  • Agent 365 Registry Sync: Pull AWS, Google, and other platform agents into your registry [GA] - Registry Sync in Agent 365 ingests agents from AWS Bedrock, Google Cloud, Databricks Genie, Anthropic Claude, and Salesforce AgentForce into the unified agent registry using API or service domain connection details. This makes cross-platform agent governance practical rather than theoretical. Connect your external AI platforms now to get a complete picture of your agent estate.

  • Managing apps built in Copilot Studio [GA] - Copilot Studio now supports full-stack app building with built-in source control, deployment stages, and version isolation on Microsoft-hosted infrastructure. Apps are created in the maker’s personal developer environment and follow your existing environment routing policies, so connector permissions, DLP policies, and sharing controls you already have in place apply automatically. Verify your environment routing and DLP policies are current before makers start using this.

  • Microsoft 365 G7: AI, Copilot, and agent governance for government [GA] - Microsoft 365 G7 bundles AI, Copilot, agent governance, security, and compliance capabilities for government agencies modernizing securely. Relevant for public sector-adjacent tenants and agencies evaluating their AI and compliance stack.

  • See every AI agent in your tenant with Agent 365 unified registry [GA] - The unified agent registry in Agent 365 surfaces all agents across Microsoft Foundry, Copilot Studio, Agent Builder, SharePoint, partner-built agents, and external providers in one view with owner, usage, and risk data attached. Most orgs currently cannot answer how many agents are running in their environment: this is the operational tool to fix that. Start your agent inventory now.

  • Microsoft 365 Copilot: Local inferencing for sovereign AI processing [GA] - Local inferencing will allow supported Copilot interactions to run AI processing within the user’s local geography, launching in Australia, India, UAE, UK, and US. GA target is December 2026. Organizations with data residency or sovereignty requirements should track this capability and plan to enable it when it reaches their region.

  • Dynamics 365 Customer Service: Knowledge-grounded quality evaluation criteria [Preview] - Quality evaluation criteria can now reference knowledge sources, letting organizations ground evaluations in approved policies and guidance. Preview in September 2026, GA target January 2027. Useful for contact centers that need evaluations to reflect documented handling standards rather than generic rubrics.

  • Dynamics 365 Customer Service: Not Applicable answer option for quality evaluation [GA] - Evaluation questions marked as Not Applicable are now excluded from scoring rather than negatively affecting results. GA target is September 2026. This prevents skewed scores when a specific criterion simply doesn’t apply to the case being reviewed.


Employee Experience

  • Microsoft Viva Insights: Leaders can now publish Power BI reports [GA] - Viva Insights is extending report publishing from analysts to leader personas (Chief Officers, Managers, and their delegates), enabling direct distribution of curated reports within their organizations through a lightweight publishing experience. GA target is October 2026. If your Viva Insights deployment uses analyst-published reports today, communicate this change to leaders who may want to self-serve their own report distribution.

Security & Compliance


Action Required

  • CVE-2026-78510 Critical Outlook and Word RCE on Mac, CVSS 9.8 - Critical · CVSS 9.8. Surfaced in the Week of 2026-09-22 digest. Network-exploitable RCE in Microsoft Outlook and Word for Mac; apply the Mac Office security update to all managed Macs immediately and notify users on unmanaged devices. This is the only CVE this week with an associated security update requiring immediate action.

  • CVE-2026-83498 Windows VBS Enclave EoP - Critical · CVSS 7.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only this cycle; confirm this was patched in your environment during the originating Patch Tuesday. Elevation of privilege in Windows Virtualization-Based Security Enclave.

  • CVE-2026-63532 Microsoft Office RCE - Critical · CVSS 7.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only this cycle; confirm this was addressed in your managed Office estate during the originating Patch Tuesday.

  • CVE-2026-68804 Microsoft Excel RCE - Critical · CVSS 7.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only this cycle; verify your Excel patch compliance against the originating Patch Tuesday release.

  • CVE-2026-55123 Microsoft PowerPoint RCE - Critical · CVSS 7.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only this cycle; verify your PowerPoint patch compliance against the originating Patch Tuesday release.

  • CVE-2026-78517 Microsoft Office Word RCE - Important · CVSS 8.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only; confirm Office Word patching is current across your managed estate.

  • CVE-2026-77901 Microsoft Office Word RCE - Important · CVSS 8.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only; confirm Office Word patching is current across your managed estate.

  • CVE-2026-78524 Microsoft Office RCE - Important · CVSS 8.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only; confirm your Office update compliance for the originating Patch Tuesday.

  • CVE-2026-78526 Microsoft Office Word RCE - Important · CVSS 8.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only; confirm your Office Word update compliance.

  • CVE-2026-62871 .NET EoP - Important · CVSS 7.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only; verify .NET patching is current across your managed endpoints.

  • CVE-2026-68798 Microsoft Excel RCE - Important · CVSS 7.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only; verify Excel patching is current.

  • CVE-2026-55039 Microsoft Excel RCE - Important · CVSS 7.8. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only; verify Excel patching is current.

  • CVE-2026-68825 Windows Bind Filter Driver EoP - Important · CVSS 7.0. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only; confirm Windows patching is current on your managed device fleet.

  • CVE-2026-63516 Microsoft SharePoint Server Spoofing - Important · CVSS 6.5. Surfaced in the Week of 2026-09-22 digest. Acknowledgment update only; if you run on-premises SharePoint Server, confirm the originating patch is applied.

  • Teams meetings security reporting: Verify your reporting mailbox configuration - The Teams “Report a Security Concern in Meetings” feature is GA in September 2026. Before it lands in your tenant, confirm your user-reported settings and reporting mailbox are correctly configured in the Defender portal so reports from meeting participants reach the right security team.

  • Teams custom apps for private/shared channels: Identify apps needing updates - Teams Admin Center will surface custom apps that need developer updates for private and shared channel compatibility, GA September 2026. Run this report immediately on availability and contact app owners for any business-critical apps that appear on the list.

  • Teams Express face enrollment: Review biometric data policy before November GA - Express face enrollment reaches GA in November 2026. Determine your organization’s stance on biometric data collection and configure the admin control to enable or disable the feature before it rolls out to your users.


Documentation Updates

Identity & Access