Critical: Support for Office LTSC 2021, and additional apps will end on October… + 4 more E8 changes (Mon 28 Sept)

28 September 2026 · 10 changes that matter, 128 reviewed.

  1. Support for Office LTSC 2021, and additional apps will end on October 13, 2026 — Office LTSC 2021, Visio LTSC 2021, and Project LTSC 2021 will reach end of support on October 13, 2026. Continued use after this date will result in no security updates, creating significant vulnerability and compliance risks. [Patch Applications]
  2. 60-Day Reminder: Windows 11, version 23H2 Enterprise and Education editions reach end of updates on November 10, 2026 — Windows 11, version 23H2 Enterprise/Education editions reach end of security updates on November 10, 2026. Continued use after this date will expose devices to unpatched vulnerabilities, requiring an upgrade to version 25H2 for ongoing protection. [Patch Operating Systems]
  3. 30-Day Reminder: Windows 11, version 24H2 and Windows 10 LTSB 2016 reaching end of updates on October 13, 2026 — Windows 11 24H2 Home/Pro and Windows 10 LTSB 2016 reach end of security updates on October 13, 2026. Unpatched systems will be vulnerable to new threats. [Patch Operating Systems]
  4. (Updated) Microsoft Entra: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication — Microsoft Entra will default to passkeys for authentication by September 2026, phasing out Microsoft-provided SMS and voice MFA by February 2027 due to their phishing vulnerability. Organisations must transition to phishing-resistant methods or procure third-party telecom providers. [Multi-Factor Authentication]
  5. Dynamics 365 Field Service: Microsoft Copilot in Field Service Mobile app — Copilot in Dynamics 365 Field Service mobile app provides frontline workers with conversational AI access to organizational data. This introduces new data access vectors and potential for sensitive information exposure via natural language queries.
  6. Dynamics 365 Field Service: Expand your service offering through subcontractors without the onboarding overhead — Dynamics 365 Field Service now allows subcontractors to update work via email without a D365 license. This introduces a new email-based agent for external collaboration, potentially expanding the attack surface for impersonation and data integrity risks.
  7. PowerPoint: Skills in Brand Kit — PowerPoint Copilot now supports custom 'skills' uploaded via Brand Kit. This allows organisations to extend Copilot's capabilities with internal knowledge, but introduces new vectors for data exfiltration or malicious code execution if not properly governed.
  8. Microsoft Copilot (Microsoft 365): Federated Copilot Connectors will support write, update and delete actions — Copilot connectors now support write, update, and delete actions in third-party services. This expands Copilot's capabilities but increases the attack surface for data manipulation through compromised user accounts. [Restrict Administrative Privileges]
  9. Microsoft Teams: Express face enrollment — Teams now offers express face enrollment for meeting recognition, improving Copilot and recap features. This introduces biometric data processing, requiring careful privacy and security consideration for Australian government agencies.
  10. Microsoft Purview: DSPM-Copilot Readiness and Data Explorer — Purview DSPM now offers Copilot readiness assessments and a data explorer. This helps security teams find sensitive data, assess exposure, and improve data security posture for Copilot deployments, reducing risk of data overexposure.