Skip to Content

Summary Microsoft Teams Direct Routing will switch to certificates from a new Certificate Authority during a validation test. Organizations using Teams Direct Routing with SBCs for TLS connections may experience connection failures if SBCs do not trust the new Root CAs. This may impact PSTN calling for affected tenants. Administrators should ensure SBCs trust the …

Read More about MC1280563: 24-hour test that switches Microsoft Teams Direct Routing SIP endpoints to certificates issued by a new CA.

Summary Planned changes to Advanced Security Information Model (ASIM) KQL functions in Microsoft Sentinel for Developers will enhance consistency and performance. Organizations using ASIM functions will need to transition to using the new parameter name, targetusername_has. Outdated parameters will be removed after ensuring they are not in use, enabling smoother transition for users. Security teams …

Read More about MC1281506: Planned breaking changes to ASIM KQL functions used by Microsoft Sentinel for Developers

Summary The Resource Assignment tab in Microsoft Project will be deprecated and not supported, marking it as a legacy experience. Existing installations will keep the tab enabled but will highlight its deprecated status; new installations will have it disabled by default. The tab can be managed via feature control until it is completely removed in …

Read More about MC1282109 Dynamics 365 Project Operations: Information regarding the end of support for the Resource Assignment tab

Summary Browsers and platforms related to Mozilla and Chrome trust stores will begin distrusting DigiCert Global Root CA (G1), affecting some organizations accessing Microsoft 365 services. Most organizations will not experience any issues, but rare legacy scenarios may lead to TLS connection failures, resulting in common error messages. No action is needed unless certificate or …

Read More about MC1282565: Exchange Online, SharePoint Online, and April 2026 industry-wide DigiCert Global Root CA (G1) distrust

Summary Power BI will retire support for embedding R and Python visuals in “Embed for your customers” and “Publish to web” scenarios. Post-retirement, reports with R or Python visuals will load but the visuals will be blank; unaffected reports will function normally. Affected users should review embedded reports and update them using supported visuals or …

Read More about MC1283817: Retirement of R and Python visuals in Embed for your customers

Summary Microsoft released out-of-band updates to resolve issues caused by the April 2026 Windows security update. Affected devices include Windows Server 2025, which may face installation failures and repeated domain controller restarts. The OOB update for Windows Server 2025 fixes both installation failure and domain controller restart issues, while updates for other versions focus only …

Read More about MC1285472: Out-of-band updates released for Windows Server to address two issues

Summary Microsoft 365 Copilot will transition API endpoints from the legacy office.com domain to cloud.microsoft domain, enhancing reliability and security. Users will not see changes in the interface or workflows, ensuring no impact on their experience as long as network configuration follows established guidelines. Organizations with restricted access to the cloud.microsoft domain or WSS connectivity …

Read More about MC1286300: Microsoft 365 Copilot transition to the cloud.microsoft domain

Summary The Global Discovery Service (GDS) API will be retired, and its REST API endpoints will no longer be available. Applications and scripts using GDS endpoints need to be identified and updated to use the Power Platform List Environments API. Testing of updated integrations against the new endpoints is required to ensure compatibility. Authentication must …

Read More about MC1253577: Information regarding the end of support for Global Discovery Service (GDS) API

Summary Windows 365 Cloud PCs with Secure Boot enabled must transition to Secure Boot 2023 certificates. Using expired 2011 certificates may lead to decreased protection against boot-level malware and inability to validate newer boot components. Cloud PCs without Secure Boot enabled are not affected by this change. IT administrators should ensure Secure Boot remains enabled …

Read More about MC1253743 Action required: Secure Boot certificate updates for Windows 365 Cloud PCs before June 2026

Summary Microsoft Registration Campaigns will support Passkeys (FIDO2) as an additional authentication method to enhance security against phishing. Changes will automatically update from Microsoft Authenticator to Passkeys (FIDO2) for eligible tenants under certain conditions. Affected users will receive Passkey registration nudges at sign-in after completing MFA to encourage registration. Administrators can opt users into Passkey …

Read More about MC1253746: Passkeys in Microsoft registration campaigns

Summary Simplification of Planner and Project licensing with specific SKUs being retired. New purchases of Planner and Project Plan 5 will no longer be available post-End of Sale. Project Online Essentials is already End of Sale and not available for new purchases. Existing customers should plan to transition to supported SKUs based on their needs. …

Read More about MC1253808 Planner and Project Online licensing: Project Plan 5 and Project Online Essentials retire from sale for EDU and DoD

Summary Licensing updates to simplify the Planner and Project SKU lineup are being implemented. Project Online will be retired on September 30, 2026. New purchases of Planner and Project Plan 5 will end after the designated date. Existing customers need to transition to supported SKUs based on their usage needs. Immediate service impact is not …

Read More about MC1253809 Planner and Project Online licensing: Project Plan 5 and Project Online Essentials retire from sale

Summary DirectQuery support in the Viva Insights Connector for Power BI is being retired, encouraging a shift to Import connectivity mode. Existing DirectQuery-based Power BI reports will not refresh, and attempts to connect using DirectQuery will fail. Unpivoted schema type and Aggregated data granularity options will also be retired. Analysts need to convert DirectQuery reports …

Read More about MC1253812 Viva Insights: Retirement of DirectQuery support in the Viva Insights Connector

Summary For tenants with more the 2000 users Copilot will no longer be available in Word, Excel, PowerPoint, and OneNote for users without a Microsoft 365 Copilot license. Users without the license will see the “Copilot Chat (Basic)” label, while licensed users will see “M365 Copilot (Premium).” Copilot will continue to be accessible in the …

Read More about MC1253858 Microsoft 365 Copilot Chat: Updates to Copilot in Word, Excel, PowerPoint, and OneNote

Summary Windows updates in April 2026 will change default Kerberos ticket behavior to AES-SHA1-only for accounts without explicit encryption type settings, potentially causing authentication issues for environments relying on RC4. Audit mode will be available until July 2026 for manual rollback; after that, only Enforcement mode will remain. Organizations should monitor System event logs for …

Read More about MC1254512: 30-Day Second deployment phase for Kerberos RC4 hardening begins with the April 2026 Windows security update

Summary Custom theming for model-driven apps using the modern look allows for branding alignment through color, font, and header style customization. Classic theming will not be supported in the modern look, necessitating a transition to custom modern themes. Custom theming enables a cohesive color scheme, customizable app header, custom logo integration, and font overrides. The …

Read More about MC1254543: Custom theming for model-driven apps is becoming generally available

Summary Microsoft is retiring support for several legacy Teams Phone devices that will no longer function post-retirement. Impacted devices will not be able to sign in, make, or receive calls. Hardware replacement is necessary, as there is no automatic upgrade path. Organizations should plan to replace affected devices and communicate this change to users. Review …

Read More about MC1254555: Teams Phones impacted by retirement of legacy authentication infrastructure [hardware replacement required]

Summary New auto-labeling actions for SharePoint and OneDrive will allow administrators to override or remove existing sensitivity labels automatically. Admins must configure these actions in the Microsoft Purview portal; they are not enabled by default. This change impacts organizations using auto-labeling policies, improving data governance and consistency. Relevant stakeholders should be informed that sensitivity labels …

Read More about MC1249431: Microsoft Purview | Information Protection – Override manually applied labels and Remove labels with Auto-labeling

Summary Microsoft Purview network data security now integrates with Island, enhancing data protection for browser-based workflows. This integration allows for the configuration of DLP policies to inspect data shared with unmanaged cloud apps. It requires admin action to enable; the feature is not activated by default. Existing Purview policies will apply automatically if the integration …

Read More about MC1249424 Microsoft Purview DLP: Unmanaged cloud app protection with Microsoft Purview and the Island Enterprise Browser

Summary Live transcription capabilities are being added to Microsoft Teams Rooms on Android, providing real-time transcription with speaker attribution and timestamps. Transcripts are displayed on the front-of-room screen. Only organizations with Teams Rooms Pro licenses will receive this feature. Users can start transcription easily from the room console; notifications will inform participants when transcription is …

Read More about MC1249432: Live transcription in Teams Rooms on Android

Summary A new soft purge mitigation action will be added in Data Security Investigations (DSI) for quick removal of sensitive items. Soft purge allows items to be deleted but remain recoverable until the retention period expires. The feature is enabled by default with no need for configuration; existing DLP, labeling, and retention policies remain unchanged. …

Read More about MC1249429: Data Security Investigations introduces new soft purge mitigation action

Summary Microsoft will retire the Semi-Annual Enterprise Channel installation option for unmanaged devices in April 2026. This change affects admins managing installation options for unmanaged devices and tenants using this channel exclusively. Existing unmanaged devices on this channel will not change until manually updated; however, the channel selection will appear grayed out if switched. Devices …

Read More about MC1249428: Retirement of the Semi-Annual Enterprise Channel installation option for unmanaged devices

Summary The Semi-Annual Enterprise Channel option will be retired from the Office Deployment Service. Organizations using the Semi-Annual Enterprise Channel will have this option removed from new deployment configurations, but existing configurations will remain unaffected. Only the Current Channel and Monthly Enterprise Channel will be available for new configurations. No immediate action is required, but …

Read More about MC1249427: Retirement of the Semi-Annual Enterprise Channel option in the Office Deployment Service

Summary Windows 2011 Secure Boot certificates will expire, requiring updates to new certificates issued in 2023 for ongoing security. Devices will still function normally but will not receive new boot-level security protections without updated certificates. Intune can be used to manage and deploy Secure Boot certificate updates on Windows clients. Administrators should enable specific settings …

Read More about MC1248382: Windows Secure Boot certificates expiring in June 2026

Summary The March 2026 security update is available for all supported Windows versions. It includes quality improvements and enhancements to the servicing stack. New high-confidence device targeting is added for Secure Boot certificate delivery. File Explorer search reliability is improved when searching across multiple drives. A warning dialog is added to confirm the trustworthiness of …

Read More about MC1248239: The March 2026 Windows security update is now available

Summary The -Credential parameter will be removed from Connect-ExchangeOnline and Connect-IppsSession cmdlets in Exchange Online PowerShell, affecting automation scripts that use it. Organizations must migrate to supported authentication methods before upgrading to module versions released after the removal. Alternatives include switching to modern authentication with MFA, using app-only authentication for non-Azure automation, or managed identity …

Read More about MC1248389: Retirement of -Credential parameter when connecting to Exchange Online PowerShell

Summary Windows Autopatch will enable hotpatch security updates by default for eligible Intune devices, improving security speed. Devices will receive updates without requiring a restart, securing them faster and saving an average of three to five days. A tenant setting to opt out of hotpatch updates will be available for those not ready for the …

Read More about MC1248388: Windows Autopatch is enabling hotpatch updates by default

Summary Updates to Microsoft 365 Apps released for Current Channel, Monthly Enterprise Channel, and Semi-Annual Enterprise Channel. Users on automatic updates from Office CDN will need no action; manual managers can download updates now. Release notes available for detailed information on each channel’s updates. Admin Impact: Medium User Impact: Low Release Start: 10 Mar 2026 …

Read More about MC1248387: Updates available for Microsoft 365 Apps for all channels

Summary Private chat will be introduced in Teams Rooms on Windows for organizers, co-organizers, and presenters during structured meetings and webinars. Two chat options will be available: one for private communication among event teams and another for all attendees. Users can switch between the two chat panels using a new dropdown on the chat button. …

Read More about MC1247896: Microsoft Teams Rooms: Private chat for organizers and presenters in structured meetings and webinars

Summary Anthropic Claude Sonnet is now available for Microsoft 365 Copilot licensed users, alongside OpenAI models. Users can select Claude Sonnet in the model selector within Copilot Chat. Regions where Anthropic is set to “Off by default” require admin opt-in for model availability. Data protection standards remain unchanged; Anthropic is a Microsoft subprocessor. Users in …

Read More about MC1247880 – Anthropic Claude Sonnet is now available in Microsoft 365 Copilot

Summary Windows Autopatch will enable hotpatch security updates by default for eligible Intune devices. Hotpatch updates allow devices to be secured faster without waiting for a restart, reducing update delay by three to five days on average. Devices will still require restarts during specified baseline months (January, April, July, and October). Recommended to ensure devices …

Read More about MC1247859: Windows Autopatch is enabling hotpatch updates by default

Summary Microsoft Agent 365 will be Generally Available (GA) after extensive customer feedback from the Frontier program. Administrator planning or evaluating Agent 365 deployment will be affected. Customers in the Frontier program will maintain access to early features and continue to provide feedback. Trial and paid options for Agent 365 will be made available before …

Read More about MC1247634: Microsoft Agent 365 Generally Available May 1, 2026

Summary Microsoft Entra passkeys will enable phishing-resistant, passwordless sign-in using Windows Hello methods. No impact on organizations unless they opt in to enable passkeys. Users can authenticate on both managed and unmanaged Windows devices through individual passkeys. Each passkey is device-bound and does not sync across devices, requiring separate registration for each account. Existing authentication …

Read More about MC1247893: Microsoft Entra passkeys on Windows now support phishing-resistant sign-in

Summary Outlook for iOS and Android will support recommended and automatic sensitivity labels during email composition. Users will be prompted to review suggested labels when sensitive information is detected. Automatic labels will be applied without any action required by the user. The feature is enabled by default for organizations with existing Microsoft Purview sensitivity labeling …

Read More about MC1247891 Outlook: Support for recommended and automatically applied sensitivity labels in Outlook for iOS and Android

Summary Copilot highlights in Viva Glint will provide AI-generated summaries of employee survey results in supported reports. The feature will automatically appear as a collapsible card at the top of relevant reports, showing key insights and trends. No additional configuration is needed; it will be available when Copilot in Viva Glint is enabled. Users must …

Read More about MC1247887: AI-generated survey insights with Copilot highlights

Summary New policy configuration options in Microsoft Purview Data Loss Prevention (DLP) enhance data security for unmanaged cloud apps and Edge for Business. Administrators gain more granular controls, including scoping collection policies by sensitivity labels and defining conditions for DLP policies. Email notifications can be configured to alert users when activities are blocked. Existing policies …

Read More about MC1247881 Microsoft Purview DLP: New policy configuration options available for inline network and Edge for Business

Summary New feature allows configuration of offline profiles using the FetchXML editor in Power Apps. Direct control over query logic for offline profiles enhances the app-building workflow. Access the FetchXML editor directly within Power Apps Studio for easier customization of data filters. No action required; message is for awareness only. For more details, visit the …

Read More about MC1247603: Configure offline profile using FetchXML editor