Critical: Prepare for Windows Update certificate rotation in 2027 + 5 more E8 changes (Sun 11 Oct)

11 October 2026 · 10 changes that matter, 247 reviewed.

  1. Prepare for Windows Update certificate rotation in 2027 — Windows Update certificates expire in 2027. Devices must have updated certificates to continue receiving security updates, critical for maintaining system integrity and protection against vulnerabilities. [Patch Operating Systems] (act before 2027-05-17)
  2. 'Record A Skill' Capability in PowerPoint Copilot — PowerPoint Copilot will allow users to record actions as reusable 'skills'. This could lead to sensitive data exposure if recorded workflows include confidential information or interact with restricted resources, bypassing existing controls. [Application Control, User Application Hardening]
  3. Microsoft Defender for Office 365: Post-delivery protection for malicious QR codes in Microsoft Teams — Microsoft Defender for Office 365 now detects malicious URLs in QR codes within Teams messages post-delivery. This enhances protection against QR code phishing and improves threat visibility for security operations.
  4. Microsoft Defender Vulnerability Management: Private preview for selected developer package vulnerability coverage — Defender Vulnerability Management now previews coverage for open-source developer package vulnerabilities (Node.js, Python, Java) on Windows. This enhances visibility into software supply chain risks, improving vulnerability management for custom applications. [Patch Applications]
  5. Microsoft Viva Insights: New Power BI report publishing capabilities for leaders — Viva Insights now allows leaders (not just analysts) to publish Power BI reports directly. This expands who can distribute sensitive organizational insights, increasing data exposure risk if not properly governed. [Restrict Administrative Privileges]
  6. Power Automate: Schedule desktop flows directly with Scheduled Triggers — Power Automate desktop flows can now be scheduled directly, bypassing cloud flows. This simplifies automation but increases the attack surface for unmanaged desktop environments and potentially unapproved automation. [Application Control, Restrict Administrative Privileges]
  7. Microsoft Word for Android: Agent Mode — Copilot Agent Mode is coming to Word on Android, enabling advanced AI drafting and reasoning on mobile. This expands the attack surface for prompt injection and sensitive data exposure via mobile devices.
  8. Microsoft Outlook: Update to default blocked file types in OwaMailboxPolicy — Microsoft is blocking .msix and .msixbundle file types in Outlook on the web and new Outlook for Windows by default. This enhances email security by preventing potentially unsafe application package attachments. [User Application Hardening]
  9. Microsoft Dataverse - Bulk generate prompt column values for existing records (backfill) — Dataverse now allows bulk AI generation of prompt column values for existing records. This introduces new risks for data integrity, compliance, and potential for AI-driven data manipulation if not properly governed.
  10. Microsoft Copilot: GPT 6.1 Sol and Claude Sonnet 5.5 beginning to roll out today — New large language models, GPT-6.1 Sol and Claude Sonnet 5.5, are rolling out to Microsoft Copilot, Copilot Studio, and M365 apps. This expands AI capabilities but requires explicit subprocessor enablement for data handling.

What we ignored

  • (Updated) Outlook (new): Right-click to customize the classic ribbon — This is a UI customization, not a security-relevant change.
  • Updated My Task experience in Planner — UI/UX update, no security relevance.
  • Windows Office Hours: October 15, 2026 — This is an informational event, not a security-relevant change.
  • Power Apps: Modern, refreshed look for the mail app — This is a UI/UX cosmetic change with no security relevance.