Active credential-theft campaigns, a hard October deadline for on-premises email security, and sweeping AI governance changes are converging this week, requiring decisions on risk, infrastructure, and identity before year-end.
Passkeys become the default in Entra ID, Entra Backup and Recovery hits GA, and advanced Intune Suite capabilities land in M365 E3/E5 - a dense week for identity hardening and endpoint licensing.
AI agents are moving from experiment to enterprise infrastructure, and this week Microsoft drew a direct line between agent governance, identity security, and the controls your organization already uses for employees. A newly documented destructive malware family and continued progress on Microsoft's Secure Future Initiative round out a week focused on resilience and accountability.
AI agents are moving from experimentation to production across Microsoft 365, bringing new productivity gains and new security obligations that require leadership attention now. This week also surfaces a maturing threat to AI infrastructure that has direct implications for data protection and compliance posture.
AI agents are moving from experimentation to production across Microsoft 365, creating new attack surfaces and compliance obligations precisely as Microsoft retires a foundational email integration standard used by many business applications. Leadership attention to both trends is warranted this week.
Six CVEs land across libxml2, GNU gzip, attr, and acl for Linux-adjacent workloads, Intune's June release doubles down on AI-era endpoint hygiene, and a malicious Chromium extension spoofing Perplexity AI is actively redirecting browser search. EWS retirement remains on track for its October 2026 deadline.
A hard deadline for legacy email connectivity, a critical Entra ID authentication overhaul, and free security capability upgrades arriving in existing Microsoft 365 licenses combine to make this a week where inaction carries measurable cost.
EWS retirement hits its final phase with a hard October 2026 deadline, Intune Suite advanced capabilities land in M365 E3/E5 by August 1, and three Entra ID legacy auth controls are heading for retirement — this week is heavy on deadlines and migration obligations.
A critical Exchange Server vulnerability, aggressive deprecation of legacy email authentication, and the arrival of AI agents that autonomously operate enterprise systems demand immediate attention from security, compliance, and IT leadership this week.
Entra Tenant Governance surfaces shadow tenants, Purview DSPM for AI hits GA, and computer-using agents in Copilot Studio are production-ready — a feature-dense week with meaningful capability unlocks across identity, data, and automation.
A wave of AI agent governance requirements, a critical on-premises Exchange vulnerability, and new Copilot licensing changes arrive simultaneously — demanding leadership attention on risk, budget, and workforce readiness.
Teams Live Events dies June 30 — migrate now. Exchange Server OWA has an active XSS CVE. Meanwhile, Purview ships posture reporting, Copilot Studio goes fully agentic with computer-use GA, and Entra tackles shadow tenant sprawl.
A critical on-premises Exchange vulnerability, retiring authentication methods, and Secure Boot certificate expirations converge this week — requiring leadership decisions on patching timelines, legacy infrastructure, and AI governance before mid-summer deadlines.
CVE-2026-42897 demands immediate patch action on all on-prem Exchange deployments, while Teams Live Events hits its June 30 retirement deadline — but this week also delivers real capability unlocks across AI agent governance, Purview posture reporting, and Entra multi-tenant visibility.
A newly disclosed malware-signing service and active supply chain attacks on developer tooling raise the threat level for organizations this week, while Microsoft advances data protection, Cloud PC management, and network security capabilities across the M365 platform.
Global Secure Access hits a GA trifecta this week with iOS client, cloud firewall for remote networks, and file-type content filtering all shipping. Pair that with Purview DLP sync dropping from 2 hours to 30 minutes and the Intune Data Warehouse v1 connector retirement, and there's real work to do.
Dirty Frag is being actively exploited on Linux endpoints. Storm-2949 proves credentials alone are enough to wipe a cloud environment. Know what needs action now.
Two hard compliance deadlines arrive in June with real operational consequences, while Microsoft's AI governance controls graduate from roadmap to live enforcement — requiring immediate decisions on identity, device security, and agent oversight.