This week in Microsoft, security, and AI: what changed and what it means for your business
Week of August 10, 2026 | A plain-English roundup for busy leaders.
Welcome back to This Week in Microsoft, Security, and AI. Every Monday, Covenant rounds up the handful of changes actually worth knowing about, so staying current is something you can do over coffee, not another chore you keep putting off.
This week the theme is familiar, but the edge is sharper: Microsoft keeps folding more security and AI capability into plans you may already pay for, while attackers keep going after the one thing that unlocks all of it – your sign-in.
There is also a patch cycle to close out, a phishing wave aimed at finance teams, and an FBI warning worth two minutes of attention.
How to read this: no jargon, no scare tactics, and no attempt to turn every headline into a project. Just what changed, why it matters, and what to do next if it applies to you.
This week’s quick list
You may already own more security than you think.
Microsoft’s 2026 Microsoft 365 pricing and packaging updates are now fully in effect. The added capabilities finished rolling out by August 1, 2026, and they include Microsoft Defender for Office 365 Plan 1 in select plans, URL time-of-click protection in Business Basic and Business Standard, expanded Intune capabilities, Microsoft Cloud PKI, Copilot Chat enhancements, Copilot Chat Analytics, and additional mailbox storage in Business plans.
Passkeys are becoming the default, and text-message MFA is winding down.
Microsoft Entra continues to push passkeys forward while moving away from Microsoft-provided SMS and voice authentication. Beginning September 1, 2026, passkeys become the default authentication experience for users enabled for SMS or voice. Microsoft-provided SMS and voice delivery retires on February 1, 2027.
Source: Microsoft Entra passkeys and SMS/voice retirement guidance.
Exchange Web Services starts being blocked October 1.
Microsoft is retiring Exchange Web Services for Exchange Online. Starting October 1, 2026, Microsoft begins blocking EWS requests in Exchange Online. EWS is an older connection method that some line-of-business apps, scanners, CRMs, backup tools, and migration tools still use behind the scenes to talk to mailboxes.
Source: Microsoft Learn: Deprecation of Exchange Web Services in Exchange Online.
Copilot in SharePoint keeps moving closer to useful business outputs.
Copilot in SharePoint continues to move beyond “find this file” and toward practical outputs: dashboard-style views, contextual prompts, and page-level actions that help people use the content already living in SharePoint. In plain terms, the information on a page can become more useful, and common questions can become a button instead of a blank prompt box.
Sources: Microsoft Support: SharePoint Button web part and Microsoft Frontier features.
A low-risk way to try Copilot: the 30-day, 25-user trial.
Microsoft introduced Copilot in 30, a partner-led Microsoft 365 Copilot Business trial built for organizations with fewer than 300 employees. It pairs a 25-user, 30-day trial with guidance to identify the people and use cases most likely to see value.
Your assistants need guardrails, not just answers.
As Copilot and AI agents move from answering questions to taking action, Microsoft continues extending Purview data protection, policy controls, AI observability, and activity visibility into those experiences. The practical question is no longer only what AI can say. It is what data it can reach and what it is allowed to do.
Sources: What’s new in Microsoft Purview, Microsoft Purview for AI agents, and Microsoft Purview protections for generative AI apps.
August security updates arrive August 11, after a record July.
Microsoft’s next Patch Tuesday is August 11, 2026. It follows a record-setting July security update cycle that addressed hundreds of vulnerabilities, including flaws reported as exploited in the wild in SharePoint Server and Active Directory Federation Services. Microsoft has also noted that AI-assisted discovery is helping uncover more issues, which can mean larger security update releases over time.
Sources: Microsoft Security Update Guide, Microsoft MSRC note on Patch Tuesday, and BleepingComputer July 2026 Patch Tuesday coverage.
A phishing wave aimed straight at Microsoft 365 sessions.
Microsoft 365 phishing is increasingly focused on stealing sessions and consent, not just passwords. Adversary-in-the-middle phishing, device-code phishing, and OAuth consent tricks can all lead to the same outcome: a user completes what looks like a real sign-in flow, and the attacker walks away with access.
Sources: FBI IC3 Kali365 PSA and DomainTools research on Microsoft 365 session hijacking.
The FBI warning is simple: attackers want the token, not the password.
The FBI is warning about Kali365, a phishing-as-a-service platform first seen in April 2026. Instead of intercepting a password, Kali365 can trick users into authorizing a Microsoft 365 session through a legitimate Microsoft device-code flow. The attacker captures OAuth access and refresh tokens, then accesses Outlook, Teams, and OneDrive without completing another MFA challenge.
Source: FBI IC3: Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens.
The bigger picture
Wouldn’t it be better if staying current on Microsoft, security, and AI did not mean doing the homework yourself every week? That is the point of this series. Covenant watches the changes so your team can spend attention on the work only you can do.
Two threads run through this week: Microsoft keeps putting more capability inside the licenses you already hold, and attackers keep aiming at the sign-in that unlocks all of it. Both point to the same next step: a clear baseline of what you own, what is turned on, what is exposed, and what to handle before the next renewal, deadline, or AI rollout.
Related Covenant solutions
Microsoft 365 Tenant Optimization Review
Right-size licensing, reduce waste, and find included Microsoft features you may not be using.
Explore tenant optimizationMicrosoft 365 Secure Score Assessment
Benchmark your Microsoft 365 security controls and prioritize the gaps that matter most.
Explore Secure ScoreFortify Microsoft Cyber Hardening
Harden identity, devices, data protection, monitoring, and AI readiness in practical stages.
Explore FortifySources and further reading
Want a second set of eyes on your Microsoft, security, and AI readiness?
Book time with Covenant. We will help you understand what changed, what matters, and where to start.
Covenant Technology Solutions | Microsoft-first. Security-first. Human.


