Microsoft’s August 2026 SharePoint Server security update covers RCE and related flaws. Farms using Workflow Manager must install KB5002799 first and follow the debug-flag step for classic setups. Admins should inventory farms and verify a known workflow after patching.
SharePoint Online and OneDrive may extend sensitivity-label support to OneNote and video files so protected content remains usable with search, eDiscovery and DLP. Admins should confirm the report, then pilot labelled notebooks and videos instead of leaving them as permanent…
SharePoint Autofill can map uploaded documents to an approved managed-metadata term set. A walkthrough covers pilot testing, the 100-term limit, human review and pay-as-you-go cost controls before broader rollout.
SharePoint Advanced Management now supplies item-level evidence of content shared through Everyone and Everyone except external users. Admins can investigate high-risk files and folders first instead of entire sites, reducing cleanup disruption and Copilot exposure risk.
Microsoft retires the preview memberOf operator in Entra dynamic groups, administrative units and entitlement auto-assignment policies on 3 November 2026. Rules stop processing and membership can go stale unless replaced beforehand.
Microsoft stops new OneDrive desktop releases for Windows 10 below 22H2 after 15 August 2026. Affected clients stay on their installed build. Endpoint teams need a pre-22H2 device inventory before the cutoff so sync failures stay diagnosable.
Exchange Online admins can transfer future meetings between user mailboxes with Invoke-ChangeMeetingOrganizer. Teams ownership, join details, recordings and linked files still need a separate handover check before offboarding.
Teams adds a tenant-level gate for apps and agents that read meeting transcripts through Microsoft Graph. Existing transcript workflows may fail until admins enable Transcript API access and verify app permissions together.
Microsoft is closing a gap that let recently accessed files from Restricted Content Discovery sites reappear in Search and Copilot. Direct access and permissions remain unchanged. Admins can treat RCD as a more consistent discoverability control.
SharePoint archiving needs decisions on discoverability, retention, and retrieval before files move. Without them, teams trade clutter for audit and search problems. A four-column inventory of keep, restrict, archive, or delete confirms owners and paths first.
Microsoft describes CaptiveCrunch, a campaign that compromises captive portals to redirect travelers into device-code and OAuth phishing. Attacks register devices in Entra and collect Microsoft 365 data, turning easy SharePoint and Teams access into a travel-network liability.
Microsoft Defender preview identifies and isolates emails carrying malicious instructions aimed at AI systems before delivery. Prompt injection becomes a practical mail-security control, not only a phishing or attachment problem, for Copilot and similar inbox workflows.
SharePoint can keep drafts separate from final documents via checkout, approval, major/minor versions, or separate authoring and published sites. Each option changes who sees unfinished content and the discipline needed when mistakes create compliance risk.
Microsoft now enforces OneDrive quotas per user licence entitlement. Over-quota drives can turn read-only, blocking file updates. Admins need reporting to spot high-usage accounts, confirm storage need, and weigh cleanup or pay-as-you-go options for commercial tenants.
The Teams PowerShell module adds stricter external access and mutual federation controls for federated group chats, alongside Windows Account Manager auth. Admins can narrow external chat risk but should test module and policy paths before production rollout.
Microsoft Purview preview DLP can exclude external-sender email from Microsoft 365 Copilot and Copilot Chat grounding. The rule checks sender domain against accepted domains, not message body, so admins must validate mail flow before relying on it.
Shared Microsoft 365 work can sit in one person's OneDrive, Teams chats, Lists, Planner, Forms, or Loop. Ownership still ties to that account, so offboarding can hide team records. Team-owned work belongs in a shared site or group with a clear retention path.
ExchangeOnlineManagement 3.10.1 fixes certificate authentication bugs that left connected admin scripts failing on Exchange cmdlets. Unattended jobs need a controlled module upgrade and regression test before production rollout.