Critical: An updated version of the September 2026 Scan Cab is available + 2 more E8 changes (Sun 4 Oct)

4 October 2026 · 10 changes that matter, 320 reviewed.

  1. An updated version of the September 2026 Scan Cab is available — An updated Exchange Server Scan Cab is available, addressing CVE-2026-96940, an Elevation of Privilege vulnerability. Re-deploying the updated Scan Cab is critical for environments using it to assess Exchange Server update compliance, ensuring timely application of security patches. [Patch Applications, Patch Operating Systems]
  2. Microsoft Edge: Commercial Journeys - AI-powered task completion for Microsoft 365 Copilot users — Microsoft Edge will use AI to proactively surface unfinished tasks for Copilot Premium users, generating content like emails and documents. This increases data exposure risk by automating content creation and task completion.
  3. Microsoft Copilot (Microsoft 365): Use Dataverse Business Skills in Sales Agent — Copilot for Sales can now use Dataverse Business Skills, allowing AI agents to follow organisation-specific sales processes and policies. This introduces new avenues for data exposure and requires careful governance of AI agent behaviour.
  4. Outlook: Draft, edit and format emails conversationally with Copilot in Outlook — Copilot in Outlook now drafts, refines, and formats emails using agentic AI. This changes how sensitive information is processed and generated, increasing the risk of data leakage and prompt injection vulnerabilities.
  5. Dynamics 365 Contact Center - Use role-based enforcement for recording and transcription downloads — Dynamics 365 Contact Center now offers role-based controls to prevent unauthorized downloading of call recordings and transcripts. This enhances data protection by separating viewing from downloading permissions, reducing data exfiltration risk. [Restrict Administrative Privileges] (act before 2026-10-31)
  6. Microsoft Excel: Excel canvas — Excel Copilot gains "Excel canvas," generating interactive reports from workbook data. These reports auto-update and are refined via natural language, potentially exposing sensitive data through new AI-driven summarization and visualization.
  7. Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs — Exchange Web Services (EWS) will require explicit application IDs for access by October 2026. This change enhances security by limiting EWS to approved applications, reducing attack surface, and forcing organisations to identify and manage EWS dependencies. [Application Control] (act before 2026-10-10)
  8. Microsoft Teams: Start side conversations during meetings — Teams meetings now allow private side conversations, potentially bypassing formal communication channels and increasing unmonitored data exchange. This impacts data governance and information security.
  9. Microsoft Purview: Data Lifecycle Management – Ensure regulatory compliance by deleting inactive OneDrives and mailboxes for departing employees — Microsoft Purview now automates deletion of inactive OneDrive and Exchange mailboxes for departed users. This reduces data sprawl and compliance risk by ensuring sensitive data is not retained unnecessarily.
  10. Microsoft Teams: Intelligent call delegation — AI-powered call delegation in Teams answers calls, gathers context, and schedules follow-ups. This introduces an AI agent as an intermediary for voice communications, potentially handling sensitive information.

What we ignored

  • Microsoft Outlook: Right-click to customize the classic ribbon — This is a UI customization, not a security-relevant change.
  • Power Apps: Modern, refreshed look for embedded model-driven apps — Purely cosmetic UI change, no security relevance.
  • Dynamics 365 Commerce: Add items to a transaction from the numpad — Operational feature with no security relevance for Australian government entities.