Critical: Reminder: Configure firewall and proxies for smooth Windows updates + 4 more E8 changes (Mon 14 Sept)
14 September 2026 · 10 changes that matter, 90 reviewed.
- Reminder: Configure firewall and proxies for smooth Windows updates — Microsoft reminds organisations to configure firewalls and proxies to allow Windows Update traffic, specifically TLS connections to *.update.microsoft.com. Failure to do so blocks critical security updates, leaving systems vulnerable. [Patch Operating Systems, Patch Applications]
- Word: Copilot edit mode is available to users in Office 365 GCC — Copilot's edit mode is now available in Word for Office 365 GCC users. This introduces AI-driven content generation and refinement capabilities directly into government documents, increasing efficiency but also expanding the attack surface for data handling and prompt injection.
- SharePoint: Changes to the FAQ web part authoring experience — SharePoint FAQ web part authoring now separates manual creation from AI-assisted generation. AI FAQ creation moves to Copilot in SharePoint, using natural language and grounding sources, impacting content governance and potential for AI-generated misinformation.
- [Whiteboard] Legacy Whiteboard migration to OneDrive — Legacy Azure-backed Whiteboards must migrate to OneDrive storage by September 25, 2026. Unmigrated Whiteboards become read-only, then are permanently deleted, risking data loss and compliance issues if not actioned. [Regular Backups]
- Microsoft Purview: Data Loss Prevention for Microsoft Cowork — Microsoft Purview DLP now extends to Microsoft Cowork, enabling unified policy enforcement across Copilot and Cowork. This protects sensitive AI interactions by preventing the use of labeled data, blocking sensitive prompts, and restricting sensitive prompts from Bing web searches.
- Updates available for Microsoft 365 Apps for Current Channel — Microsoft has released routine security and feature updates for Microsoft 365 Apps on the Current Channel. Applying these updates is crucial for maintaining security posture and patching known vulnerabilities. [Patch Applications]
- Microsoft Entra: Prepare for Microsoft to disable unused or unsuccessful SMS first-factor sign-in — Microsoft will automatically disable SMS first-factor sign-in in Entra tenants with no recent successful usage due to high fraud risk. This enhances security by removing a phishing-susceptible authentication method. [Multi-Factor Authentication]
- Microsoft Viva Engage: Microsoft Entra permissions required for community and membership administration — Viva Engage community and membership administration now requires corresponding Microsoft Entra permissions. Users with only Viva Engage roles will lose admin capabilities, enforcing a stronger identity-based access control model. [Restrict Administrative Privileges]
- Dynamics 365 Customer Service -Resolve customer emails autonomously with AI — Dynamics 365 Customer Service will gain AI-driven autonomous email resolution. This feature processes customer emails end-to-end without human intervention, leveraging enterprise knowledge and custom agents to respond automatically. It shifts from case-first to intent-driven resolution, reducing manual effort and accelerating response times.
- Microsoft Teams: Coordinated meetings support on Teams Rooms on Android — Teams Rooms on Android now support coordinated meetings with touch boards. This increases the attack surface for meeting devices and requires careful network segmentation and access control to prevent unauthorized access and data exfiltration.