Active threat campaigns are targeting your workforce through fake IT support in Microsoft Teams, while a wave of Microsoft patches and a critical Exchange Server deadline demand immediate leadership attention. This week carries material security and operational risk for organizations of every size.
Four Critical CVEs land across Azure AD B2C, Copilot Studio, Azure AI Language, and Microsoft Fabric - plus GPT-6 Astra and Claude Fable 5.1 go live in Copilot, and Exchange hybrid shops face a hard version-floor deadline starting this week.
Active social-engineering attacks and newly discovered AI infrastructure threats are raising the security stakes for every Microsoft 365 organization this week, while a wave of AI, collaboration, and device management improvements resets expectations for what productivity looks like at scale.
Autopilot device association reaches GA with hardware-backed pre-enrollment trust, Remote Help gets unattended Windows access, and two Critical-severity CVEs land alongside a heads-up from Exchange Online that legacy identifier properties may be on their way out.
Official Microsoft deployment and setup guides for Intune, Defender, Entra, Copilot, Purview, and Viva, organized by Modern Work practice area, plus what actually changes across Commercial, GCC, GCC High, and DoD.
A plain definition of Modern Work: Microsoft's practice areas spanning identity, endpoints, collaboration, AI, employee experience, and security, explained for engineers and executives.
This week's updates center on compliance obligations tied to AI-generated data and faster response to data loss incidents, both areas with direct bearing on regulatory standing and cyber insurance posture.
Exchange Server on-premises requires urgent security patching, and Microsoft's sweeping vulnerability disclosures across Office, Teams, and Windows signal a high-pressure week for IT and compliance teams. Organizations running their own email infrastructure or relying on unpatched Windows endpoints face the most immediate exposure.
Exchange Server SE gets its August security updates while CU1 slips further, and a wave of CVE acknowledgment updates signals an active patch cycle. Engineers also get new Defender for Identity tooling, granular Purview audit logs on the horizon, and a useful roundup of Windows device recovery options.
Active ransomware operations, a major software supply chain attack, and the arrival of AI agent security controls make this a week where security posture decisions carry direct financial and compliance weight.
Entra Tenant Governance hits GA for multi-tenant control at scale, Defender for Identity expands sensor v3.x coverage to AD FS, AD CS, and Entra Connect, and the Copilot Domain Exclusion feature gets quietly rolled back - a lot moved this week.
A Russian state-sponsored threat actor is actively targeting business travelers, and AI agents are emerging as a new governance and security frontier that demands executive attention this week.
Defender for Office 365 Plan 1 lands in M365 E3, Writeback for Cloud-Managed Remote Mailboxes hits GA, and Midnight Blizzard is actively targeting hospitality sign-in portals - a rich week of capability unlocks alongside real threat intelligence to act on.
Active credential-theft campaigns, a hard October deadline for on-premises email security, and sweeping AI governance changes are converging this week, requiring decisions on risk, infrastructure, and identity before year-end.
Passkeys become the default in Entra ID, Entra Backup and Recovery hits GA, and advanced Intune Suite capabilities land in M365 E3/E5 - a dense week for identity hardening and endpoint licensing.
AI agents are moving from experiment to enterprise infrastructure, and this week Microsoft drew a direct line between agent governance, identity security, and the controls your organization already uses for employees. A newly documented destructive malware family and continued progress on Microsoft's Secure Future Initiative round out a week focused on resilience and accountability.
AI agents are moving from experimentation to production across Microsoft 365, bringing new productivity gains and new security obligations that require leadership attention now. This week also surfaces a maturing threat to AI infrastructure that has direct implications for data protection and compliance posture.
AI agents are moving from experimentation to production across Microsoft 365, creating new attack surfaces and compliance obligations precisely as Microsoft retires a foundational email integration standard used by many business applications. Leadership attention to both trends is warranted this week.
Six CVEs land across libxml2, GNU gzip, attr, and acl for Linux-adjacent workloads, Intune's June release doubles down on AI-era endpoint hygiene, and a malicious Chromium extension spoofing Perplexity AI is actively redirecting browser search. EWS retirement remains on track for its October 2026 deadline.
A hard deadline for legacy email connectivity, a critical Entra ID authentication overhaul, and free security capability upgrades arriving in existing Microsoft 365 licenses combine to make this a week where inaction carries measurable cost.
EWS retirement hits its final phase with a hard October 2026 deadline, Intune Suite advanced capabilities land in M365 E3/E5 by August 1, and three Entra ID legacy auth controls are heading for retirement — this week is heavy on deadlines and migration obligations.
A critical Exchange Server vulnerability, aggressive deprecation of legacy email authentication, and the arrival of AI agents that autonomously operate enterprise systems demand immediate attention from security, compliance, and IT leadership this week.
Entra Tenant Governance surfaces shadow tenants, Purview DSPM for AI hits GA, and computer-using agents in Copilot Studio are production-ready — a feature-dense week with meaningful capability unlocks across identity, data, and automation.
A wave of AI agent governance requirements, a critical on-premises Exchange vulnerability, and new Copilot licensing changes arrive simultaneously — demanding leadership attention on risk, budget, and workforce readiness.
Teams Live Events dies June 30 — migrate now. Exchange Server OWA has an active XSS CVE. Meanwhile, Purview ships posture reporting, Copilot Studio goes fully agentic with computer-use GA, and Entra tackles shadow tenant sprawl.
A critical on-premises Exchange vulnerability, retiring authentication methods, and Secure Boot certificate expirations converge this week — requiring leadership decisions on patching timelines, legacy infrastructure, and AI governance before mid-summer deadlines.
CVE-2026-42897 demands immediate patch action on all on-prem Exchange deployments, while Teams Live Events hits its June 30 retirement deadline — but this week also delivers real capability unlocks across AI agent governance, Purview posture reporting, and Entra multi-tenant visibility.
A newly disclosed malware-signing service and active supply chain attacks on developer tooling raise the threat level for organizations this week, while Microsoft advances data protection, Cloud PC management, and network security capabilities across the M365 platform.
Global Secure Access hits a GA trifecta this week with iOS client, cloud firewall for remote networks, and file-type content filtering all shipping. Pair that with Purview DLP sync dropping from 2 hours to 30 minutes and the Intune Data Warehouse v1 connector retirement, and there's real work to do.
Dirty Frag is being actively exploited on Linux endpoints. Storm-2949 proves credentials alone are enough to wipe a cloud environment. Know what needs action now.
Two hard compliance deadlines arrive in June with real operational consequences, while Microsoft's AI governance controls graduate from roadmap to live enforcement — requiring immediate decisions on identity, device security, and agent oversight.