See what is exposed, wasted, or ready for AI. Start your Technology Readiness Review.

Week of August 24, 2026: A Plain-English Roundup For Busy Leaders.

New Every Monday

This week in Microsoft, security, and AI: what changed and what it means for your business

Week of August 24, 2026 | A plain-English roundup for busy leaders.

Welcome back to This Week in Microsoft, Security, and AI.

Welcome back to This Week in Microsoft, Security, and AI.

This week had a single thread running through it: the login. Microsoft set a date to stop texting your people a code to sign in. Attackers spent the week going after credentials and live sessions rather than software flaws. And on the AI side, Microsoft started treating AI agents the way it treats users and devices — something you inventory, license and can switch off. Different headlines, same underlying question: who’s getting through your front door, and how would you know.

How to read this: no jargon, no scare tactics, and no turning a headline into a project. For each item we answer 3 things — what changed, why it matters, and what to do next if it applies to you. Most of these won’t apply to you. The 1 or 2 that do are worth 5 minutes.

This week’s quick list

01Microsoft set the end date for text-message and phone-call sign-in codes — passkey prompts start reaching your people on September 1, and there’s no opt-out after February 1, 2027.
02The two Copilot apps became one on August 18, with a new web address and 3 features retired.
03Legacy Microsoft Whiteboard boards are permanently deleted on September 5 — export anything you want to keep.
04Microsoft 365 usage reports are moving to new web addresses, which can quietly break reporting for anyone who filters traffic by URL.
05Microsoft put AI agents under central management in public preview — you can now see them, block them and hold them to a license.
06Microsoft patched a flaw where 1 click on a link could make the consumer Copilot hand over data from connected accounts.
07OpenAI paused its largest planned training run over security concerns and previewed a way for customers to keep their data on their own infrastructure.
08A Windows flaw already used in real attacks hits its federal patch deadline tomorrow — and installing the update isn’t enough without a reboot.
09Researchers found a campaign selling company directories pulled straight out of Microsoft cloud tenants using stolen employee logins.
10The FBI and CISA updated their Medusa ransomware advisory: 500+ victims, and the attackers get in with phishing and unpatched software, then abuse ordinary remote-support tools.
In Microsoft This Week
01
Identity & access

Microsoft is retiring text-message and phone-call sign-in codes

Microsoft has published firm dates for ending Microsoft-provided SMS and voice multifactor authentication in Entra ID, the service behind your Microsoft 365 logins. Starting September 1, 2026, tenants with users set up for text or phone-call codes will have those users automatically enabled for passkeys, and Microsoft will begin nudging them to register one at their next sign-in. Users can snooze the prompt.

The hard date is February 1, 2027. After that, Microsoft-provided SMS and voice are retired. Anyone whose only sign-in method is a text or a phone call will hit a registration prompt they can’t dismiss. There is no opt-out from that enforcement — it applies to every tenant. Organizations with a genuine regulatory need for phone-based codes can bring their own telecom provider, with configuration available from October 30, 2026.

What it means for you

If any of your staff still receive a text with a 6-digit code to log in, that’s ending, and the clock is public. This is a good change on the merits — codes sent by text can be intercepted or relayed by an attacker in real time, and passkeys can’t be. But it touches every employee, and the worst version of it is discovering on a February morning that your bookkeeper can’t get into email. The version you want is a planned rollout this fall with a heads-up and a 10-minute walkthrough.

How Covenant helps

Rolling out passkeys is an identity project, not a checkbox — you need a list of who’s affected, a backup method for people who lose a device and a plan for shared or frontline accounts. That’s exactly the work in Fortify, Covenant’s Microsoft Cyber Hardening solution, and we’d rather do it in October than in a February scramble.

Sources: Microsoft Learn — Microsoft-provided SMS and voice retirement

02
Apps & rollout

The two Copilot apps became one

On August 18, 2026, Microsoft merged the Microsoft 365 Copilot app and the consumer Copilot app into a single app called Microsoft Copilot — new name, new icon, and a new commercial web address moving from m365.cloud.microsoft to copilot.cloud.microsoft, with an automatic redirect. Your security, compliance and privacy settings didn’t change, and because the underlying application ID is the same, existing policies keep working. Early desktop preview opened August 18, with broader rollout beginning mid-September.

Three features were retired the same day: Copilot Group Chat, Podcasts and Deep Research in the consumer app. Content in Group Chat threads was not carried forward. The merged app does add clearer visual separation between work and personal accounts — account labels, a green shield for work accounts and different background colors.

What it means for you

Two practical things. If your network filters traffic by web address, the new copilot.cloud.microsoft address needs to be allowed or people will find Copilot simply stops loading. And if anyone on your team was using Group Chat, Podcasts or Deep Research, that’s gone — worth a short internal note so nobody spends an afternoon hunting for it. The work-versus-personal visual cue is a genuine small win if you’ve ever worried about staff pasting company information into a personal assistant.

How Covenant helps

Copilot isn’t magic — it’s math plus your data, and rollouts go sideways on network rules and unannounced changes rather than on the technology. Copilot Readiness & Rollout covers the allow-list, the permissions review and the change note your team actually reads.

Sources: Microsoft Support — Changes to the Microsoft Copilot app · Microsoft Partner Center announcements, August 2026

03
Data retention

Old Whiteboard boards get permanently deleted on September 5

Microsoft is finishing its move to OneDrive-backed whiteboards and retiring the older ones. The migration tool for legacy enterprise whiteboards was retired on August 22, 2026 — that date has already passed. On September 5, 2026, remaining legacy whiteboards are permanently deleted, with no recovery option. The standalone Whiteboard app is deprecated on September 14, 2026, after which enterprise users work with Whiteboard inside Teams.

What it means for you

This is the only item in this week’s roundup with permanent data loss attached to a date. If your teams brainstormed on Whiteboard over the last few years — project plans, org charts, retrospective boards — anything still sitting in a legacy board disappears in about 2 weeks. Migration is no longer an option, but export still is. Most companies will find they don’t need any of it. It’s the ones who do that we worry about.

How Covenant helps

Deadlines like this are why we read Microsoft’s message center on our clients’ behalf. Always-On IT Operations means someone is watching the retirement calendar and telling you which dates actually touch your business, before the recovery window closes.

Sources: Microsoft 365 message center — MC1441775, Whiteboard retirement

04
Admin & reporting

Microsoft 365 usage reports are moving to new web addresses

In a message center post published around August 21, 2026, Microsoft announced that the usage reports in the Microsoft 365 admin center are moving to new web addresses as part of a domain consolidation. Nothing about the reports, the data or who can see them changes. Old and new addresses run side by side for at least 30 days, and any redirect happens no earlier than September 17, 2026. Commercial tenants move first, with government clouds following through early September.

What it means for you

This only bites if your firewall or web filter allows specific addresses rather than allowing Microsoft broadly — which is common in regulated environments and in any network somebody locked down carefully years ago. If that’s you and nobody updates the list, license and usage reporting quietly stops working after the redirect. You’d notice it as “why can’t I see who’s actually using our licenses” during a renewal conversation, which is the worst possible time.

How Covenant helps

Usage reporting is how you find out you’re paying for 30 licenses and using 22. A Microsoft 365 Tenant Optimization Review makes sure the reporting still works, and then turns it into a right-sized license position instead of a spreadsheet nobody opens.

Sources: Microsoft 365 message center MC1459136 — usage reports moving to new domains

In AI This Week
05
AI agent governance

AI agents now have an inventory and an off switch

On August 18, 2026, Microsoft moved multi-tenant agent management into public preview in the Microsoft 365 admin center. Administrators can now see a consolidated list of AI agents across the tenants they manage, add agents, install them across selected tenants, review their permissions and — this is the important verb — block them. Cross-tenant access is authorized through delegated admin permissions, so nobody gets standing access they shouldn’t have. Managing agents needs no extra license; seeing agent risk and activity requires a Microsoft Agent 365 license.

What it means for you

Over the past year, AI agents have quietly shown up inside businesses the way SaaS apps did a decade ago — someone useful turns one on, and there’s no list. Microsoft has now decided agents are things you inventory, license and revoke, the same as users and laptops. That’s a signal about where the questions are heading. Your insurer, your auditor or your largest customer is going to ask “which AI tools have access to your data, and who approved them,” and “we’re not sure” is a bad answer even when the honest answer is “not many.”

How Covenant helps

The goal isn’t to say no to AI. It’s to know what’s connected and what it can reach, so AI becomes a trusted teammate instead of a liability. Covenant AI Workspace Powered by Goodweek gives your team a governed place to work with AI — with the inventory, permissions and oversight already handled.

Sources: Microsoft 365 message center MC1456781 — public preview, manage agents across multiple tenants · Multi-tenant agent management in the Microsoft 365 admin center · Microsoft Learn — agent settings in the Microsoft 365 admin center

06
Copilot & AI security

Microsoft fixed a flaw where 1 click could make Copilot leak your connected accounts

Researchers at Varonis disclosed 3 chained weaknesses in Copilot Personal — the consumer assistant at copilot.microsoft.com, not Microsoft 365 Copilot. Nicknamed CoSnitch and tracked as CVE-2026-24301, the flaw meant a specially built link could make Copilot run an attacker’s instructions the moment the page loaded, inside the victim’s own signed-in session. In testing, the researchers pulled email bodies and sender details, calendar entries with attendees, file names from cloud storage and prior chat history — all from accounts the user had already connected. Microsoft shipped the fix on August 18, 2026, and the researchers found no evidence anyone had used it in the wild.

There’s a second, more stubborn piece. A malicious web page, once summarized by Copilot, could write instructions into the assistant’s long-term memory — where they survived password changes, session revocation and device re-enrollment, and stayed active until the user deleted them by hand.

What it means for you

The lesson isn’t “AI is dangerous.” It’s that an assistant connected to your mail, calendar and files should be treated like an employee with those same permissions — because that’s effectively what it is. Two things worth doing regardless of this specific bug: look at which accounts your team has connected to any AI assistant and disconnect the ones nobody is actually using, and treat a link that opens an AI chat with the same caution as a link that opens a login page.

How Covenant helps

Most AI risk in a small business isn’t exotic — it’s over-connected accounts and over-shared files that were already too open before AI arrived. A Microsoft 365 Secure Score Assessment gives you an honest baseline on identity, sharing and app permissions, and a short list of what to fix first.

Sources: Varonis Threat Labs — CoSnitch · Microsoft Security Update Guide — CVE-2026-24301 · The Hacker News coverage

07
AI governance

OpenAI hit the brakes on its own training run, then offered customers a way to keep their data

Two notable posts from OpenAI in one week. On August 18, 2026, the company disclosed that it had temporarily paused reinforcement-learning training on its newest models for about 2 weeks while it hardened and tested its own research environments, and that its largest planned frontier training run remains on hold. The reasons were a security incident involving a partner and early evidence that an upcoming model may reach the “critical” cybersecurity threshold in OpenAI’s own safety framework. The new controls it described are unglamorous and familiar: sandboxing, network isolation, continuous testing and monitoring — at roughly 20% additional compute cost.

Then on August 19, OpenAI committed to keeping zero data retention available for eligible API customers and previewed Private Safety Processing, an approach where safety monitoring happens on customer-controlled infrastructure, or on OpenAI infrastructure encrypted with keys the customer holds. OpenAI receives only an alert category and severity, never the content. It’s in testing with early customers, with broader rollout planned for September.

What it means for you

If you’ve been told “we can’t use AI because we can’t let a vendor keep our data,” that objection is getting a real answer — and it’s worth revisiting rather than treating as settled. If you’ve been told AI vendors move too fast to trust, note that the fastest-moving one just paused its flagship training run and published why. Neither is a reason to rush. Both are reasons to have the conversation with your compliance obligations on the table instead of in the abstract.

How Covenant helps

For businesses in healthcare, financial services or government work, the question is never “is AI useful” — it’s “can we show where the data went.” Covenant AI Workspace Powered by Goodweek is built so AI adoption stays defensible, with data handling you can explain to an auditor.

Sources: OpenAI — Pacing model development in an era of cyber-critical capabilities · OpenAI — Offering zero data retention for frontier models

In Security This Week
08
Patch management

A Windows flaw already used in real attacks hits its federal deadline tomorrow

CVE-2026-68820 is a Windows flaw in a core networking driver that lets someone who already has a low-privilege foothold on a machine promote themselves to full system control. Microsoft patched it on August 11, 2026, and CISA added it to the Known Exploited Vulnerabilities catalog the same day, because it was already being used in real attacks before the patch existed. Under CISA’s risk-based timelines, internet-facing Windows systems were due by August 14 and internal Windows endpoints are due August 25, 2026 — tomorrow. There’s no workaround; the driver can’t be disabled or firewalled.

One detail matters more than the CVE number: the fix replaces a kernel driver, so the vulnerable version stays loaded until the machine restarts. A patch report showing 100% installed and 0% rebooted is not a patched fleet. For scale, Microsoft’s August update covered roughly 400 vulnerabilities including 3 zero-days — and July was larger still, at around 570.

What it means for you

The specific flaw isn’t the story. The volume is. At roughly 400 fixes a month, “we install updates when we notice them” isn’t a patch strategy, and the gap between a patch shipping and attackers using it is now measured in days. What you want is a monthly cycle with verification — including confirmed reboots — and a report you can hand to an insurer or an auditor without caveats.

How Covenant helps

Always-On IT Operations includes managed patching with monthly verification reporting, so “are we patched” has a documented answer instead of an optimistic one. If nobody can currently tell you what percentage of your machines rebooted after last Tuesday, that’s the gap.

Sources: Qualys — CVE-2026-68820 and CISA BOD 26-04 requirements · BleepingComputer — August 2026 Patch Tuesday · Tenable — August 2026 Patch Tuesday analysis

09
Identity & credentials

Someone is selling company directories pulled out of Microsoft cloud tenants

Researchers at Hudson Rock reported on August 16, 2026 — picked up widely on August 17 and 18 — that a threat actor is advertising large employee directories that appear to have been exported directly from organizations’ Microsoft Entra tenants. The listed data includes names, work email addresses, phone numbers, employee IDs, job titles, departments, reporting lines, group memberships, service accounts and lists of who holds global administrator rights. Named organizations include several very large global brands.

The researchers were careful about the cause, and so are we: they said the method isn’t conclusive, but assessed it’s most likely that attackers used credentials harvested by information-stealing malware on employee devices, not a flaw in Microsoft’s cloud. Related work from Arctic Wolf in early August described a parallel pattern — voicemail-themed phishing that captures both the password and the multifactor code in real time, after which attackers quietly read payroll, invoice and banking email without changing a single setting.

What it means for you

Your company directory is a phishing kit. Reporting lines, job titles and the names of your administrators are exactly what someone needs to write a convincing “quick favor from the CFO” email. The practical takeaway is about how you respond to malware: if a laptop turns up infected with an information stealer, resetting the password is not enough. Stolen sign-in tokens keep working after a password change. You have to revoke the active sessions too.

How Covenant helps

A Security Score Assessment gives you an honest baseline across identity, endpoints and email — including whether your team can actually revoke sessions when it matters, and who currently holds administrator rights you’d forgotten about.

Sources: Hudson Rock — Azure exfiltration campaign · Arctic Wolf — Payroll Pirates: strange new tides in business email compromise

10
Ransomware & remote access

The FBI and CISA updated the Medusa ransomware advisory: 500+ victims

On August 18, 2026, CISA, the FBI and the Department of Health and Human Services published an update to their joint Medusa ransomware advisory. The victim count rose from over 300 to over 500 organizations across critical infrastructure, based on FBI investigative findings through April 2026. HHS was added as a co-author, reflecting how heavily healthcare has been targeted. The advisory also expanded its list of software flaws the group exploits to get in.

The two entry points haven’t changed: phishing for credentials, and unpatched software exposed to the internet. What’s worth reading closely is what happens next. Medusa operators abuse legitimate remote-support tools — the advisory names AnyDesk, Atera, ConnectWise, N-able, SimpleHelp, Splashtop and others — because those tools look like normal IT activity. Then they delete backup snapshots before encrypting.

What it means for you

Two questions, and you should know both answers. First, which remote-access tools does your business actually use? If the answer is “one,” then any other remote tool installing itself is an alarm, and you can configure that alarm. Second, if your files were encrypted tonight, could you restore them from a backup the attacker couldn’t reach? Medusa specifically goes after backups, which means online backups sitting in the same environment aren’t insurance — they’re part of the blast radius.

How Covenant helps

Making backups and remote access defensible is core to Fortify, Covenant’s Microsoft Cyber Hardening solution — offline, immutable backups you’ve actually tested, and an allowed list of remote tools so anything else triggers a look.

Sources: CISA — #StopRansomware: Medusa Ransomware (AA25-071A) · Joint advisory PDF, updated August 18, 2026

The bigger picture

Here’s a small story from this week that says more than any single item above. On Thursday, Microsoft disclosed a maximum-severity flaw in Entra ID — the service behind every Microsoft 365 login — and its own bulletin initially marked it as exploited in the wild. That’s the kind of headline that ruins a Friday. By August 21, Microsoft had corrected the record: the flaw was never exploited, it was already fully fixed on Microsoft’s side, and there was no action for customers to take.

Both things were true 48 hours apart. The difference between panic and a calm Monday was somebody reading past the headline.

That’s the job we’ve signed up for. There were roughly 400 Microsoft fixes this month, a dozen message center posts, 3 AI vendor announcements and 1 corrected CVE — and out of all of it, most businesses have maybe 2 real action items: get ahead of the passkey change before February, and make sure last Tuesday’s updates actually rebooted. Everything else is context.

You didn’t start your business to track Microsoft retirement dates. We did. If you’d like an honest baseline of where your Microsoft environment, your security posture and your AI readiness actually stand — no scare tactics, no shelfware, just a clear picture and a short list of what to fix first — that’s a conversation, not a project.

Related Covenant solutions

Want a second set of eyes on your Microsoft, security, and AI readiness?

on your Microsoft, security, and AI readiness?

Bring us the environment you actually have — not the one you wish you had. We’ll give you a clear baseline, a short list of what matters and a next step you can afford.

Covenant Technology Solutions | Microsoft-first. Security-first. Human.

Scroll to Top