This week in Microsoft, security, and AI: what changed and what it means for your business
Week of August 17, 2026 | A plain-English roundup for busy leaders.
Welcome back to This Week in Microsoft, Security, and AI. Every Monday, Covenant rounds up the handful of changes actually worth knowing about, so staying current is something you can do over coffee, not another chore you keep putting off.
This week’s theme is deadlines and defaults. Microsoft is switching off some old shortcuts, raising minimum versions on phones and tablets, and moving Copilot into a single app — and several of those dates land in the next four weeks, not next year.
On the security side, both Microsoft and Cisco shipped fixes for flaws attackers were already using.
How to read this: no jargon, no scare tactics, and no attempt to turn every headline into a project. Just what changed, why it matters, and what to do next if it applies to you.
This week’s quick list
Signing in with just a text message is no longer an option.
Microsoft has retired SMS first-factor sign-in for Microsoft Entra ID Free tenants, effective August 11, 2026. That’s the setup where someone signs in with only a registered phone number and a one-time code by text — no username, no password. Microsoft pointed to rising fraud against that method as the reason.
To be clear about what did not change: text messages used as a second factor still work. If your people enter a password and then get a code by text, nothing breaks today.
Sources: MC1448374 and Microsoft Learn: SMS-based authentication.
The Exchange Web Services shutdown starts October 1, and there is now a way to protect the apps you still need.
Exchange Web Services, or EWS, is an older way for software to talk to Microsoft 365 mailboxes. Microsoft begins retiring it on October 1, 2026, with full retirement starting April 1, 2027. Microsoft updated its guidance on August 13 to explain a new tenant setting, EWSAllowedAppIDs, that lets administrators name the specific applications allowed to keep using EWS.
The important detail: after October, simply having EWS switched on will not be enough. Only the apps on your approved list will keep working.
Sources: MC1447678 and Microsoft Exchange Team Blog: Introducing EWSAllowedAppIDs.
Older iPhones, iPads and Macs are aging out of management.
Microsoft announced on August 14 that Intune will require iOS and iPadOS 18 or later for device management and app protection, taking effect shortly after Apple releases iOS and iPadOS 27 later this year. A companion announcement raises the bar for Macs to macOS 15 and later for enrollment and management.
Microsoft has not published a hard date yet, because it depends on Apple’s release timing.
One place to decide which apps and AI agents your staff can install.
Microsoft is finishing a long-running project to unify app and agent management across the Teams admin center, the Microsoft 365 admin center, Outlook and the Copilot app. In an update dated August 13, Microsoft said the installation phase begins rolling out in late August 2026 and should complete by mid-September 2026.
Source: MC796790 — Microsoft 365 unifies app and agent management.
The two Copilot apps are becoming one, and a few features are retiring.
Microsoft began rolling out a merged Copilot app in mid-August, bringing the consumer Copilot and Microsoft 365 Copilot together under one name, one icon and one sign-in experience, with personal, work and school accounts kept separate inside it.
Alongside the merge, three features retire starting August 18: Group Chat, Podcasts and Deep Research. Deep Research is being replaced by a feature called Researcher.
Sources: Windows Central, The Register and MC1454108.
Excel’s experimental =COPILOT formula retires on September 14.
Microsoft confirmed that beginning September 14, 2026, the =COPILOT function in Excel will no longer be available. It was a preview feature offered through the Excel Insider and Frontier programs, letting people call Copilot from inside a cell.
AI keeps getting cheaper, which is a good reason not to lock yourself in.
On August 13, Google released Gemini 3.7 Flash, a faster model aimed at coding and agent work, at an introductory price of half what the previous version cost per million tokens — just three weeks after the version it replaces.
Source: Google: Gemini 3.7 Flash.
August’s Microsoft patches included a flaw attackers were already using.
Microsoft’s August 11 Patch Tuesday was a large one — 421 vulnerabilities by Rapid7’s count, including 236 in Windows alone, with more spread across Office, SharePoint, Exchange, Azure and developer tools.
The one that matters most is CVE-2026-68820, a flaw in a core Windows networking driver that lets an attacker raise privileges on a machine they have already reached. Rapid7 lists it as “exploitation detected.”
Sources: BleepingComputer, Rapid7 and SecurityWeek.
A Cisco VPN flaw was used to knock firewalls offline.
Cisco published an advisory on August 11 for CVE-2026-20349, a flaw in the remote-access VPN service on its Secure Firewall ASA and Threat Defense products. An unauthenticated attacker can send a crafted request and force the device to reboot — no password, no user interaction.
Sources: Cisco security advisory and BleepingComputer.
Android phones running Microsoft Defender need an app update.
In a message dated August 14, Microsoft said devices must be running Microsoft Defender for Endpoint for Android version 1.0.9107.0101 or later to keep working through an infrastructure change expected by mid-September 2026. Older versions may lose mobile threat protection.
The bigger picture
Look at this week’s list together and a pattern shows up: almost none of it is new capability. It is Microsoft turning off old shortcuts, raising minimum versions and consolidating where decisions get made.
That work is genuinely good for security — and it is also the kind of work that generates a quiet stream of deadlines nobody put on your calendar. That is the job we take off your plate. Covenant reads the change notices, sorts the three that need action from the dozens that do not, and handles the rest so your team can spend attention on the work only your organization can do.
If any of this raised a question, the simplest next step is an honest baseline: what you own, what is actually turned on, what is exposed and what has a date attached to it before your next renewal or AI rollout.
Related Covenant solutions
Microsoft 365 Tenant Optimization Review
Right-size licensing, reduce waste and find included Microsoft features you may not be using.
Explore tenant optimizationMicrosoft 365 Secure Score Assessment
Benchmark your Microsoft 365 security controls and prioritize the gaps that matter most.
Explore Secure ScoreFortify Microsoft Cyber Hardening
Harden identity, devices, data protection, monitoring and AI readiness in practical stages.
Explore FortifySources and further reading
Want a second set of eyes on your Microsoft, security, and AI readiness?
Book time with Covenant. We will help you understand what changed, what matters, and where to start.
Covenant Technology Solutions | Microsoft-first. Security-first. Human.


