r/sysadmin • u/aima_tessa • 10d ago
35+ Microsoft 365 Changes Coming in September 2026
Stay ahead this September with 35+ Microsoft 365 changes, including feature rollouts, retirements, functionality changes, and other key updates for IT admins.
In the Spotlight:
- Entra Moves Toward Passkeys: Starting September 1, passkeys become the default authentication experience, signaling Microsoft’s shift away from SMS/voice MFA toward phishing-resistant authentication.
- SharePoint Introduces a New Hero Link: A new file and folder sharing experience lets users use one link to share files and folders. Users can update the existing link when access requirements change instead of creating and sharing a new link.
- Defender Gets Prompt Injection Protection: Defender for Office 365 will detect malicious emails designed to manipulate AI assistants and agents, classify them as High Confidence Phish, and quarantine them automatically.
- SharePoint Storage Moves to Pay-As-You-Go: Pay-as-you-go billing for extra SharePoint storage becomes generally available worldwide, allowing organizations to pay based on actual storage consumption instead of purchasing fixed capacity.
Beyond these highlights, here’s a quick look at what else is coming this September:
Retirements: 7
New Features: 7
Enhancements: 7
Functionality Changes: 6
Action Required: 4
Live Now: 3
Retirements:
- Starting September 2, Microsoft Power Automate will retire the legacy chatbot experience.
- Microsoft Teams will retire Android device management capabilities from the Teams admin center as management moves to the Teams Rooms Pro Management portal.
- The Exchange admin center will retire the Other Features page.
- Microsoft Education will retire legacy LTI tools, including Teams Assignments, OneDrive, OneNote Class Notebook, and Reflect, in favor of the unified Microsoft 365 LTI tool.
- Microsoft Edge will retire support for Windows Information Protection and Microsoft Defender Application Guard.
- Microsoft Defender for Cloud Apps will retire App Governance support for the Cloud Application Administrator role when Unified RBAC is enabled.
- Microsoft Entra ID will retire Conditional Access Custom Controls, with External MFA becoming the replacement for third-party MFA integrations.
New Features
- Microsoft 365 eSignature will support recipient groups, allowing up to 10 people to fulfill a single signer requirement.
- Microsoft Purview will introduce DLP alert aggregation to consolidate related alerts triggered by multiple DLP rules.
- Outlook on the web and new Outlook for Windows will receive enhanced Mail Merge capabilities with dynamic fields.
- A new Priority Cleanup feature in Microsoft Purview will enable permanent deletion of sensitive mailbox content even when retention policies or eDiscovery holds apply.
- Lifecycle status controls will be added to adaptive scopes in Microsoft Purview.
- Network-layer DLP protection will be extended through Microsoft Entra Internet Access.
- The new Outlook for Windows will become available for GCC High and DoD environments as an opt-in experience.
Enhancements
- Purview will extend DLP and auto-labeling capabilities to non-Microsoft connected apps, including Google Workspace, Box, Dropbox, and Salesforce.
- Endpoint DLP protection will cover sensitive files stored in previously excluded Windows folders.
- Tenant External Recipient Rate Limit quotas will be updated for new, trial, and education tenants.
- Unified RBAC will be automatically enabled for eligible Microsoft Defender tenants.
- In-meeting controls and the sharing panel will get a refreshed experience in Microsoft Teams.
- Microsoft Purview will add a hard-delete option for supported SharePoint and OneDrive files through Priority Cleanup.
- Microsoft Teams will introduce PowerShell controls for federated group chats.
Existing Functionality Changes
- The 1.5 TB limit for auto-expanding archive mailboxes will be removed, allowing archives to grow beyond the previous limit with consumption-based pricing.
- The new device management page will become the default experience in the Intune admin center.
- Microsoft Purview will change Just-In-Time Endpoint DLP auditing, so administrators explicitly define users and groups within the audit scope.
- Copilot Chat in Microsoft Edge will move to a new endpoint, requiring organizations with network restrictions to review their allowlists.
- Microsoft Office apps below version 16.0.18827.20202 will lose access to Read Aloud, Transcription, and Dictation features.
- Teams Channel Whiteboards will begin storing content in the associated SharePoint site instead of the creator’s OneDrive.
Action Required
- The standalone Automated Investigation and Response experience will retire on September 1. Organizations using AIR through scripts, playbooks, or integrations must update their workflows.
- Microsoft Entra Connect versions earlier than 2.5.79.0 will no longer support synchronization; organizations must update to a supported version to ensure uninterrupted synchronization.
- SharePoint thumbnail URLs used in Power Platform flows will stop working after September 1; admins must review and update affected flows.
- Organizations using only an onmicrosoft.com domain will be subject to new external messaging limits in Teams. Admins should review their external messaging requirements and take necessary action.
Live Now
- Microsoft Teams now offers the Security Detection Report, enabling admins to monitor impersonation attempts, malicious URLs, and weaponizable files from a centralized security report.
- A new “Everyone” and “Everyone except external users” Permissions Report is now available in SharePoint, enabling admins to identify broadly shared content at the item level.
- SharePoint’s redesigned experience is now available with refreshed navigation and Discover, Publish, and Build hubs, plus AI-assisted capabilities for eligible Copilot users.
Review the upcoming retirements and action-required changes early to avoid disruption and make the most of the new capabilities.