See what is exposed, wasted, or ready for AI. Start your Technology Readiness Review.

Week of July 27, 2026: A Plain-English Roundup For Busy Leaders.

New Every Monday

This week in Microsoft, security, and AI: what changed and what it means for your business

Week of July 27, 2026 | A plain-English roundup for busy leaders.

Welcome to the first edition of This Week in Microsoft, Security, and AI. Each Monday, we will post a short read on the Covenant blog covering the changes worth knowing about so staying current is something you can do over coffee, not another chore you keep putting off.

Between Microsoft updates, new AI tools, and a steady drip of security headlines, there is more noise than any busy leader can track. Most of it does not matter to you. A few things genuinely do, especially when they affect your invoice, your help desk, your risk, or your next AI decision.

How to read this: no jargon, no scare tactics, and no attempt to turn every headline into a project. Just what changed, why it matters, and what to do next if it applies to your business.

This week’s quick list

1Microsoft 365 pricing is now a renewal conversation.
2Exchange Server 2016 and 2019 need a migration plan.
3Windows 10 is already out of standard support.
4July Patch Tuesday included flaws already under attack.
5Teams security belongs in the phishing conversation.
6Copilot readiness starts with files, permissions, and governance.
7Your team may already be using AI with company data.
8Scammers are disguising malware as popular AI tools.
In Microsoft This Week
01
Microsoft 365 licensing

Microsoft 365 prices went up on July 1.

If your bill looks higher, you are not imagining it. Microsoft commercial pricing changes are now in effect for select Microsoft 365 plans, including Business Basic and Business Standard. Existing customers remain on current pricing until renewal, which means the most important date is your own renewal date.

What it means for you

Most tenants have unused seats, stale accounts, duplicate tools, or users assigned to plans that no longer match their work.

How we help

A Microsoft 365 Tenant Optimization Review shows where licensing waste exists and what security value you may already own.

Source: Microsoft 365 pricing and packaging updates.

02
Exchange lifecycle

Exchange Server 2016 and 2019 are now firmly in migration territory.

If you still run your own email server, this is the one to circle. Microsoft says support for Exchange Server 2016 and 2019 ended on October 14, 2025, and organizations should be planning migration to Microsoft 365, Office 365, or Exchange Server Subscription Edition.

What it means for you

This is no longer a someday project. Unsupported email infrastructure increases risk and makes future security work harder.

How we help

We plan and run Exchange to Microsoft 365 migrations with a focus on continuity, security, and user experience.

Sources: Microsoft Exchange end-of-support roadmap and BleepingComputer coverage of the ESU reminder.

03
Endpoint planning

Windows 10 is already out of standard support.

Windows 10 reached end of support on October 14, 2025. Extended Security Updates can provide a temporary bridge, but they do not include new features or general support. They are a planning tool, not a destination.

What it means for you

If a chunk of your fleet is still on Windows 10, you need to know which devices can move to Windows 11, which need replacement, and which need short-term coverage.

How we help

Always On IT Operations helps keep device lifecycle, patching, and endpoint support from becoming a last-minute scramble.

Source: Microsoft Windows 10 Extended Security Updates guidance.

04
Patch Tuesday

The month’s Microsoft patches included flaws already under attack.

July’s Patch Tuesday was unusually large. Tenable reported that Microsoft addressed 569 CVEs, including three zero-days, two of which were exploited in the wild. The affected areas included SharePoint Server and Active Directory Federation Services.

What it means for you

If you run on-premises Microsoft infrastructure, patching needs an owner, a cadence, and a way to verify that critical systems are not left behind.

How we help

Fortify Microsoft Cyber Hardening helps tighten the Microsoft controls attackers target first, while managed operations keeps the basics moving.

Source: Tenable July 2026 Patch Tuesday analysis.

05
Teams security

Teams is now part of the phishing conversation.

Email is not the only place people are targeted. Microsoft Teams can also be used for spam, phishing, or impersonation attempts, especially when external chat settings and user verification habits are loose.

What it means for you

Your team may trust a Teams message more than an email. That makes external access settings, guest permissions, MFA, and simple verification practices worth reviewing.

How we help

A Microsoft 365 Secure Score Assessment reviews the Microsoft tenant controls that affect identity, collaboration, Teams, and data exposure.

Source: Microsoft Teams guidance for external chat phishing and impersonation.

In AI This Week
06
Copilot readiness

Thinking about Copilot? Get your files in order first.

A new survey reported that many organizations have delayed or cancelled Microsoft Copilot deployments because leaders are worried AI could expose confidential data, especially through old SharePoint sharing links and permissions that were never cleaned up.

What it means for you

Copilot is genuinely useful, but it reads what users can already access. Clean up permissions first and AI becomes much easier to trust.

How we help

AI/Copilot Readiness helps map permissions, data exposure, governance, licensing, and rollout planning before AI expands across the business.

Source: Infosecurity Magazine coverage of CoreView’s Microsoft 365 security research.

07
Shadow AI

Your team is probably already using AI with company data.

Recent SMB-focused security commentary highlights the growth of Shadow AI: employees using public AI tools without IT approval. Often, the intent is good. People are trying to move faster. The risk is that company information can leave the business through tools no one is governing.

What it means for you

Whether or not you have officially rolled out AI, it may already be in use. The fix is usually not a blanket ban. It is a safer option, clear rules, and better visibility.

How we help

Covenant helps teams define safe AI use, prepare Microsoft 365 for AI, and choose a sanctioned workspace so staff can get the benefit without sending sensitive data into unmanaged tools.

Source: TNGlobal: Shadow AI for SMBs.

08
AI scams

Scammers are disguising malware as popular AI tools.

Attackers follow attention, and right now attention is on AI. Security researchers have reported malware campaigns disguised as popular AI services, including fake downloads that imitate tools people recognize.

What it means for you

When staff go hunting for an AI tool on their own, a fake installer is an easy trap. Software approval, endpoint protection, and practical training matter.

How we help

Managed endpoint protection through Always On IT Operations helps catch bad downloads, while Fortify sets stronger guardrails around users, devices, and data.

Source: TNGlobal: Shadow AI for SMBs.

The bigger picture

Wouldn’t it be better if staying current on Microsoft, security, and AI did not mean doing the homework yourself every week? That is the whole point of this series. We watch the changes so you can spend your attention on the work only you can do.

If any of this raised a question for your business, the simplest next step is a clear baseline: what you own, what you use, what is exposed, and what should be handled before the next renewal, support deadline, or AI rollout.

Want a second set of eyes on your Microsoft and AI readiness?

Book time with Covenant. We will help you understand what changed, what matters, and where to start.

Scroll to Top