Skip to Content

Summary Microsoft 365 Copilot Cowork is moving to general availability worldwide, while Frontier remains the early-access channel for new capabilities. Frontier Cowork is changing to usage-based billing, with a grace period for existing users and required billing setup to keep access after the grace period ends. Admins need to configure pay-as-you-go billing and review spending …

Read More about MC1393468 Cowork in Frontier: New Value + Usage-based Billing

Summary Copilot Cowork is now generally available worldwide for eligible users, with a new experience that adds multi-model capabilities, plugins, updated skill management/navigation, Microsoft Purview integration, and branded templates/image creation. Access is limited to users with a Microsoft 365 Copilot license and requires usage-based billing through Copilot Credits; without billing enabled, users cannot use Cowork. …

Read More about MC1393471: Copilot Cowork generally available today

Summary Microsoft Teams is adding new admin controls for governing how applications and agents access meeting transcripts through the Microsoft Graph API. The controls apply to transcripts with and without speaker attribution, giving admins more granular control over transcript data access. Tenant administrators managing Teams and Graph API permissions are affected, especially where apps or …

Read More about MC1393806: Graph API transcript access controls for administrators

Summary Microsoft is retiring support for Microsoft Defender for Endpoint on Amazon Linux 2 (ARM64); devices running AL2 on AMD64/x86_64 are not affected. The last supported MDE agent for AL2 (ARM64) is version 101.25122.0004; later Defender releases will not install on that architecture. Admins must identify devices running Amazon Linux 2 (ARM64), prevent upgrades beyond …

Read More about MC1392568: Microsoft Defender for Endpoint: Support for Amazon Linux 2 (ARM64) retiring October 31, 2026

Summary The OneDrive (Consumer) connector used in Power Platform (flows, apps, and agents) is being deprecated and will be removed; OneDrive for Business connector is not affected. After the deprecation starts, new flows/apps/agents will no longer be able to use the consumer connector; existing items must be reviewed and migrated before retirement. IT must inventory …

Read More about MC1392593: Information regarding the retirement of the OneDrive (Consumer) Connector

Summary File-level archiving for Microsoft 365 Archive will be turned on by default for tenants that already have Microsoft 365 Archive configured. A new “Archive” action will appear in SharePoint on the web for users with edit permissions; archived files are moved to a cold storage tier and must be reactivated to access. Admins can …

Read More about MC1387809 Microsoft 365 Archive: File-level archiving will be enabled by default for existing customers

Summary Microsoft Defender for Endpoint on Linux now retrieves internal configuration updates from new service URLs; these must be allowlisted per your tenant type. Affected: organizations using Defender for Endpoint on Linux endpoints (agents require outbound access to the listed URLs). Admin action: review firewall/proxy rules and allowlist the single URL that matches your tenant …

Read More about MC1388718 Microsoft Defender for Endpoint: Update to Linux connectivity requirements with new service URLs to allowlist

Summary Windows security updates will enforce Kerberos RC4 hardening on domain controllers, removing Audit mode as a rollback option after the final phase. Systems, service accounts, applications, appliances, and non‑Windows Kerberos implementations that still rely on RC4 may experience authentication failures unless remediated. Admins must detect RC4 dependencies (check System event log for Kerberos-related events) …

Read More about MC1388721 30-Day Reminder: Final deployment phase for Kerberos RC4 hardening begins with the July 2026 Windows security update

Summary Outgoing screensharing in Microsoft Teams VDI with the new SlimCore optimization will capture and process shared content on the virtual machine (VM) instead of the endpoint device; enabled by default in supported client versions. Affected: organizations using Teams in VDI environments (Azure Virtual Desktop, Windows 365, Citrix, Amazon WorkSpaces, Omnissa) and users who share …

Read More about MC1387528 Microsoft Teams VDI: Outgoing screensharing changes for SlimCore-based optimization

Summary Microsoft Purview Endpoint DLP Just-in-time protection audit logging is changing from automatic logging to an explicitly scoped setting: admins must configure which users or groups have activities audited. Affected: Purview/Endpoint DLP administrators who manage Just-in-time protection and Activity explorer visibility; audited vs blocked scopes determine whether activities are logged or enforcement occurs. Admin action …

Read More about MC1387575 Microsoft Purview | Endpoint Data Loss Prevention: Scope Just-in-time audit by user or group

Summary Update network/firewall to allow outbound ports 50118 and 50119 and the domain *.rtmpingest.mcr.teams.cloud.microsoft for RTMP-In streaming into Teams meetings, webinars, and town halls. Affected: admins who manage Teams meetings/webinars/town halls and event organizers using external hardware or software encoders; existing RTMP-In events will continue to function through end of 2026 but new events may …

Read More about MC1387814: RTMP-In port and domain changes required

Summary Storage capacity entitlement report in Power Platform admin center was incorrectly displaying data for certain Dynamics 365 applications. A misconfiguration caused incorrect storage capacity from base licenses to be reported with attach and premium licenses. A fix will ensure reporting aligns with standard licensing policy regarding storage entitlements. Attach licenses will no longer show …

Read More about MC1384733: Information about an update to storage capacity entitlement reporting

Summary Dynamics 365 Sales and Dynamics 365 Customer Service license entitlements are not granting expected read-only access to Dynamics 365 Finance and Operations apps. Affected users: anyone using Sales or Customer Service licenses who rely on read-only access to Finance & Operations data. No admin action is required; Microsoft will deploy a fix automatically (see …

Read More about MC1384395 Dynamics 365: Sales and Customer Service licenses are not granting read-only access to finance and operations

Summary Microsoft is retiring the Sora video generation experience (Sora 2) that is available through the Frontier program. Affected: organizations participating in the Frontier program that have access to the Sora experience in Copilot Create. After retirement, users will not be able to generate new videos using Sora; previously generated videos will remain accessible. Microsoft …

Read More about MC1384407: Retirement of Sora video generation experience (Frontier)

Summary Windows 365 Flex shared Cloud PCs will automatically reset to a provisioning snapshot at sign-out, removing both user and system data between user sessions unless you opt out at the provisioning policy level. Snapshots are created during provisioning and refreshed every 24 hours; resets occur on sign-out or session timeout and may show Cloud …

Read More about MC1381108: Snapshot-based reset for Windows 365 Flex shared Cloud PCs

Summary Enforced lifecycle will be applied to unlicensed OneDrive accounts so accounts that remain unlicensed/unpaid go through staged restrictions and can ultimately be permanently deleted if not preserved. Affected tenants: any tenant with OneDrive accounts that became unlicensed after license removal or user deletion. Admins can preserve data by reassigning OneDrive licenses, enabling pay-as-you-go billing …

Read More about MC1381110: Retention enforcement for unlicensed OneDrive accounts

Summary Windows 365 will change the default PowerShell execution policy applied to Cloud PCs during provisioning to RemoteSigned at the LocalMachine scope. This affects organizations that run unsigned downloaded PowerShell scripts on Cloud PCs or that enforce a stricter MachinePolicy (for example AllSigned) via Intune or Group Policy, which can cause provisioning/resize/restore failures. Admins should …

Read More about MC1381113 Windows 365: PowerShell execution policy change during Cloud PC provisioning

Summary File-level archiving for SharePoint Online (Microsoft 365 Archive) is entering General Availability: users with edit permissions will see a new “Archive” action in SharePoint on the web and files are moved to a cold storage tier while remaining discoverable. Feature is enabled by default for all SharePoint sites in tenants that have Microsoft 365 …

Read More about MC1381114: Microsoft 365 Archive: File-level archiving General Availability

Summary Data privacy message published about Microsoft Teams meeting recordings affecting your organization. Details are available only in the Microsoft 365 admin center to Global Administrators or users assigned the Message Center Privacy Reader role. IT admins should sign in to the Message Center to read the full privacy notice and follow any remediation or …

Read More about MC1333582: Issue with Teams meeting recordings [Previously MC1293001]

Summary Microsoft Teams PowerShell on Windows will default to using Web Account Manager (WAM) for Connect-MicrosoftTeams sign-ins (interactive, -Credential, -AccountId/IWA). A temporary -DisableWAM parameter is available to bypass WAM for a single connection; it will be removed in a future release. Preview availability begins in the Teams PowerShell preview (v7.8.1); admins should review and update …

Read More about MC1338817: Microsoft Teams PowerShell: Web Account Manager (WAM) becomes the default authentication broker

Summary Work IQ API is transitioning from public preview to general availability and will use consumption-based billing via Copilot Credits for usage through third-party agents and applications. Administrators must configure credit-based billing and new cost management controls in the Microsoft admin center (enable billing, create spend policies, set usage limits and alerts, and monitor the …

Read More about MC1332672: General availability of the Work IQ API with Copilot Credits billing

Summary Microsoft is introducing Microsoft Scout, the first always-on “Autopilot” personal agent that can act on behalf of users across Microsoft 365 apps (Teams, Outlook, OneDrive, SharePoint) and runs locally on user desktops. Microsoft Scout is available today as a Frontier (preview) desktop experience on Windows and macOS but is OFF by default and requires …

Read More about MC1332811: Introducing Microsoft Scout, an always-on personal agent

Summary Microsoft is updating PowerPoint Live in Teams and Teams Rooms devices must run the latest supported Teams Rooms app versions to preserve PowerPoint Live functionality (synchronized media playback, real-time inking/annotation). Affected devices: Microsoft Teams Rooms on Windows and Android; impacts Teams/PowerPoint experiences in meeting rooms. Action for IT: inventory and update Teams Rooms apps …

Read More about MC1332812 Action required: Update Teams Rooms app to maintain PowerPoint Live functionality

Summary Teams Events and Teams eCDN service plans are currently missing from Microsoft 365 E7 licenses; Microsoft will backfill the missing service plans during a remediation rollout. Affected parties: organizations using or moving to Microsoft 365 E7, licensing admins, and users who create or manage Teams events (webinars, live events, town halls). Admins must manually …

Read More about MC1332813 Microsoft 365 E7: missing Teams events and eCDN service plans – temporary impact and mitigation

Summary OneDrive mobile apps (iOS and Android) will block sign-ins that use SharePoint Server on-premises accounts; personal Microsoft accounts and Microsoft 365/Entra accounts are unaffected. Affected users: anyone signing into OneDrive mobile with SharePoint Server (on-premises 2016/2019) credentials; admins managing identity/SharePoint Server environments need to act. Recommended admin actions: identify affected users/devices, migrate identities to …

Read More about MC1332814: OneDrive mobile apps will no longer support SharePoint Server on‑premises sign-ins

Summary Microsoft is removing SMB signature inspection events (ActionType == “NetworkSignatureInspected” with SignatureName == “SMB_Client”) from Defender for Endpoint Advanced Hunting. Affected: security administrators and analysts with custom detection rules, saved/scheduled hunting queries, or automated workflows that reference SMB_Client signature events. No admin opt-out: the change is on by default; other network signature inspection events …

Read More about MC1330888 Upcoming change to Microsoft Defender for Endpoint Advanced Hunting: removal of SMB signature data

Summary SSPR will require users to have explicitly registered authentication methods for password reset verification; directory attributes (mobilePhone, businessPhone, otherMails) will no longer be accepted unless registered. This affects all users (including admins) in tenants with SSPR enabled across Public cloud and US Government clouds (GCC, GCC High, DoD). Admins must review registration coverage, ensure …

Read More about MC1325414: Microsoft Entra ID SSPR will require registered authentication methods starting September 7, 2026

Summary Microsoft 365 Copilot will support real-time desktop screen and mobile camera sharing during Copilot voice sessions; vision is enabled by default and processes only content shared during the active session. Admins can disable screen and camera sharing in the Microsoft 365 admin center (Copilot > Settings > Copilot Actions > Screen and camera sharing); …

Read More about MC1325421: Support for real-time screen sharing in Copilot voice sessions

Summary Conditional Access policies scoped to “Register security information” will now be enforced when users set up Windows Hello for Business (WHfB) or register macOS Platform SSO credentials. Users who do not meet the targeted Conditional Access grant requirements (MFA, authentication strength, trusted location, FIDO2 key, etc.) will be blocked from completing WHfB or macOS …

Read More about MC1326253: Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration

Summary Microsoft Teams will enforce Information Barriers (IB) between users in the same tenant even when they participate in external group chats, calls, or meetings; this enforcement is enabled by default for tenants that have IB configured. Applies to Teams chat, group chat, meetings, and calls across desktop, web, and mobile clients; existing IB policies …

Read More about MC1326258: Information Barriers enforcement for same‑tenant users in external group chats

Summary Microsoft 365 Copilot will support real-time desktop screen and mobile camera sharing during Copilot voice sessions; vision is enabled by default and processes only content shared during the active session. Admins can disable screen and camera sharing in the Microsoft 365 admin center (Copilot > Settings > Copilot Actions > Screen and camera sharing); …

Read More about MC1325421: Support for real-time screen sharing in Copilot voice sessions

Summary SSPR will require users to have explicitly registered authentication methods for password reset verification; directory attributes (mobilePhone, businessPhone, otherMails) will no longer be accepted unless registered. This affects all users (including admins) in tenants with SSPR enabled across Public cloud and US Government clouds (GCC, GCC High, DoD). Admins must review registration coverage, ensure …

Read More about MC1325414: Microsoft Entra ID SSPR will require registered authentication methods starting September 7, 2026

Summary Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport will only return transport rule data when the caller explicitly includes -EventType TransportRuleHits or -EventType TransportRuleActionHits. Affected parties: Exchange Online administrators, messaging/security/compliance teams, and any automation, scheduled jobs, or reports that rely on these two cmdlets. Action required: review and update all PowerShell scripts and automation that call these cmdlets to …

Read More about MC1323250 Action Required: Update scripts using Get-MailDetailTransportRuleReport and Get-MailTrafficPolicyReport

Summary Visio desktop’s built-in export to Power Automate (BPMN export) is being retired; the Export button/pane and Show Flow Markup will be removed from the Visio UI. Affected users: anyone who uses Visio desktop to export BPMN diagrams as Power Automate cloud flows; existing flows exported from Visio will continue to run and Visio diagrams/templates …

Read More about MC1323265: Power Automate flow export from Visio is being retired in July

Summary A Data Privacy notice (Microsoft Online Services Subprocessor Disclosure) is available in the Microsoft 365 Message Center. The full disclosure can only be viewed by a Global Administrator or someone assigned the Message Center Privacy Reader role; sign in to the Admin Center > Message center to read it. Applies broadly to the Microsoft …

Read More about MC1323272 Data Privacy: Microsoft Online Services Subprocessor Disclosure

Summary Microsoft is retiring the Microsoft 365 Usage Analytics Power BI template app; new downloads will be blocked and existing installations will stop receiving data and refreshes at end of support. Affected: admins and analysts who use the template app for Microsoft 365 usage, adoption, or activity reporting; organizations that rely on dashboards built from …

Read More about MC1324288: Microsoft 365 Usage Analytics Power BI template app will be retired

Summary Free upgrade path for eligible K‑12 devices from Windows 11 Home to Windows 11 Pro Education; admin initiation is required (run Clipupgrade.exe) and a restart completes the upgrade. Applies only to K‑12 Education tenants with a verified Academic Entra domain; admins must sign in with a school IT administrator account to validate eligibility. Upgraded …

Read More about MC1324289: [EDU] Free upgrade path to Windows 11 Pro Education for K-12

Summary Microsoft is changing Dataverse ingress IPs which will consolidate and narrow the service tag IP ranges used by Dataverse infrastructure. This impacts outbound connections to Dataverse (including Dataverse TDS) if your network/firewall or web proxy allow-lists specific IP addresses instead of the PowerPlatformInfra regional service tags. Admins must review Power Platform URLs and IP …

Read More about MC1319299: Information about upcoming change to ingress IPs

Summary Microsoft published updated mitigation guidance and a Microsoft-provided script for CVE-2026-45585 (Windows BitLocker security feature bypass) that replaces previously documented manual mitigation steps. The mitigation applies to BitLocker on Windows 11 (24H2, 25H2, 26H1) and Windows Server 2025 — review inventory for these OS versions and BitLocker usage. Administrators should review the Microsoft Security …

Read More about MC1318295: Mitigation guidance updated with a new script for CVE 2026 45585