Critical: The September 2026 Windows security update is now available + 3 more E8 changes (Mon 21 Sept)

21 September 2026 · 10 changes that matter, 118 reviewed.

  1. The September 2026 Windows security update is now available — Microsoft has released the September 2026 security updates for Windows, including improvements to Secure Boot certificate deployment and the servicing stack. Prompt installation is critical to maintain system integrity and protect against known vulnerabilities. [Patch Operating Systems]
  2. Microsoft Copilot (Microsoft 365): [Copilot Extensibility] Users in GCC-M will able to use custom engine agents — GCC-M users can now deploy custom Copilot agents. This introduces new risks for data exfiltration and unauthorized access, requiring immediate governance and security policy enforcement for agent identities and data handling. [Application Control, Restrict Administrative Privileges]
  3. Microsoft Purview: Data Lifecycle Management-Legacy Teams retention policies covering Copilot will be treated as Teams-only — Existing Microsoft Teams retention policies will no longer cover Copilot interactions. This change means Copilot data will not be retained by these legacy policies, potentially creating compliance gaps for AI-generated content.
  4. Microsoft Copilot (Microsoft 365): Copilot Cowork for Government Clouds — Copilot Cowork, an AI agent capable of delegating and executing tasks based on user intent and M365 data, is now available in GCC. This introduces autonomous AI capabilities, increasing data exposure and the attack surface.
  5. Outlook: Multi Account Search — Outlook now allows searching across multiple mailboxes simultaneously. This increases the risk of inadvertent data exposure if users have access to sensitive mailboxes they shouldn't be searching.
  6. Microsoft Teams: Customize blocked file extensions for Weaponizable File Protection — Teams now allows customisation of blocked file extensions for weaponizable file protection. This enhances an organisation's ability to tailor security policies, reducing risk from malicious file types. [Application Control]
  7. Microsoft Purview: Data Loss Prevention-Upgraded inline protection for Microsoft Entra-managed apps in Edge for Business — Microsoft Purview DLP now offers enhanced inline data protection for Entra-managed apps in Edge for Business, simplifying configuration and expanding policy capabilities through Conditional Access integration. This improves data loss prevention for sensitive information.
  8. Microsoft Teams: Ask Copilot from Search on Mobile — Copilot is now accessible directly from the Teams mobile search bar, allowing users to query and interact with Copilot without leaving search. This expands the attack surface for data exposure and prompt injection on mobile devices.
  9. Microsoft Purview: Data Loss Prevention-Expanded inline protection for unmanaged apps in Edge for Business — Microsoft Purview DLP now offers expanded inline protection for sensitive data in Edge for Business when users interact with a broader range of unmanaged generative AI applications. This enhances data security by preventing exfiltration to unsanctioned AI services.
  10. Microsoft Purview | Data Lifecycle Management - Graph API Support for archive mailboxes — Microsoft is retiring Exchange Web Services (EWS) for archive mailboxes by April 2027. Organizations must migrate any applications, scripts, or third-party solutions using EWS for archive data to Microsoft Graph APIs to maintain access and compliance. [Regular Backups]