See what is exposed, wasted, or ready for AI. Start your Technology Readiness Review.

Week of August 10, 2026: A Plain-English Roundup For Busy Leaders.

New Every Monday

This week in Microsoft, security, and AI: what changed and what it means for your business

Week of August 10, 2026 | A plain-English roundup for busy leaders.

Welcome back to This Week in Microsoft, Security, and AI. Every Monday, Covenant rounds up the handful of changes actually worth knowing about, so staying current is something you can do over coffee, not another chore you keep putting off.

This week the theme is familiar, but the edge is sharper: Microsoft keeps folding more security and AI capability into plans you may already pay for, while attackers keep going after the one thing that unlocks all of it – your sign-in.

There is also a patch cycle to close out, a phishing wave aimed at finance teams, and an FBI warning worth two minutes of attention.

How to read this: no jargon, no scare tactics, and no attempt to turn every headline into a project. Just what changed, why it matters, and what to do next if it applies to you.

This week’s quick list

01Microsoft finished rolling more security and Copilot value into base plans. You may already own it.
02Passkeys are becoming the default sign-in direction in Microsoft Entra as text and call codes wind down.
03Exchange Web Services starts being blocked October 1, 2026 – a real deadline for older apps and integrations.
04Copilot in SharePoint keeps moving closer to dashboards, prompts, and useful business outputs.
05A 30-day, 25-user Copilot Business trial is available for smaller organizations through CSP.
06Governing what Copilot and AI agents can reach is now an operational setting, not a someday idea.
07August security updates arrive August 11, right after July’s record-setting batch.
08Phishing campaigns are hijacking Microsoft 365 sessions, not just passwords.
09The FBI is warning that attackers can steal Microsoft 365 access tokens through device-code phishing.
In Microsoft This Week
01
Licensing & packaging

You may already own more security than you think.

Microsoft’s 2026 Microsoft 365 pricing and packaging updates are now fully in effect. The added capabilities finished rolling out by August 1, 2026, and they include Microsoft Defender for Office 365 Plan 1 in select plans, URL time-of-click protection in Business Basic and Business Standard, expanded Intune capabilities, Microsoft Cloud PKI, Copilot Chat enhancements, Copilot Chat Analytics, and additional mailbox storage in Business plans.

What it means for you

Some protection and productivity value you might have budgeted for separately may now sit inside licenses you already own. The catch is that included does not mean configured.

How Covenant helps

A Microsoft 365 Tenant Optimization Review shows what you own, what is turned on, and where you can cut duplicate tools or unused licensing.

Source: Microsoft 365 pricing and packaging updates.

02
Identity

Passkeys are becoming the default, and text-message MFA is winding down.

Microsoft Entra continues to push passkeys forward while moving away from Microsoft-provided SMS and voice authentication. Beginning September 1, 2026, passkeys become the default authentication experience for users enabled for SMS or voice. Microsoft-provided SMS and voice delivery retires on February 1, 2027.

What it means for you

This touches every user in your tenant. Fewer passwords means fewer resets and less to phish, but the rollout needs a plan so users do not get confused or locked out.

How Covenant helps

A Microsoft 365 Secure Score Assessment is the natural starting point for a passwordless plan that fits your users.

Source: Microsoft Entra passkeys and SMS/voice retirement guidance.

03
Lifecycle

Exchange Web Services starts being blocked October 1.

Microsoft is retiring Exchange Web Services for Exchange Online. Starting October 1, 2026, Microsoft begins blocking EWS requests in Exchange Online. EWS is an older connection method that some line-of-business apps, scanners, CRMs, backup tools, and migration tools still use behind the scenes to talk to mailboxes.

What it means for you

If a vendor tool or internal integration still relies on EWS, it can quietly stop working this fall. The fix is usually manageable, but only if you know which tools are affected before the deadline.

How Covenant helps

Keeping tenants current, configured, and understood is part of Always-On IT Operations.

Source: Microsoft Learn: Deprecation of Exchange Web Services in Exchange Online.

In AI This Week
04
Copilot productivity

Copilot in SharePoint keeps moving closer to useful business outputs.

Copilot in SharePoint continues to move beyond “find this file” and toward practical outputs: dashboard-style views, contextual prompts, and page-level actions that help people use the content already living in SharePoint. In plain terms, the information on a page can become more useful, and common questions can become a button instead of a blank prompt box.

What it means for you

Small teams can get more out of SharePoint without standing up a separate reporting tool, provided the underlying permissions and data are in good shape.

How Covenant helps

Copilot Readiness & Rollout maps permissions, data exposure, governance, and adoption before AI expands across your organization.

Sources: Microsoft Support: SharePoint Button web part and Microsoft Frontier features.

05
Copilot adoption

A low-risk way to try Copilot: the 30-day, 25-user trial.

Microsoft introduced Copilot in 30, a partner-led Microsoft 365 Copilot Business trial built for organizations with fewer than 300 employees. It pairs a 25-user, 30-day trial with guidance to identify the people and use cases most likely to see value.

What it means for you

You can test Copilot with a real group of users before committing broadly. That is the honest way to find out whether it earns its keep in your environment.

How Covenant helps

Copilot Readiness & Rollout helps you pick the right pilot users, set guardrails, and measure whether the trial is actually paying off.

Source: Microsoft Partner Center July 2026 announcements.

06
Governing AI

Your assistants need guardrails, not just answers.

As Copilot and AI agents move from answering questions to taking action, Microsoft continues extending Purview data protection, policy controls, AI observability, and activity visibility into those experiences. The practical question is no longer only what AI can say. It is what data it can reach and what it is allowed to do.

What it means for you

The biggest AI risk for most organizations is still oversharing: an assistant surfacing something it should not. These controls help, but they work best when permissions, labels, and data ownership are already in decent shape.

How Covenant helps

Covenant AI Workspace and Copilot Readiness & Rollout give your staff a clear path to use AI with practical guardrails.

Sources: What’s new in Microsoft Purview, Microsoft Purview for AI agents, and Microsoft Purview protections for generative AI apps.

In Security This Week
07
Patch management

August security updates arrive August 11, after a record July.

Microsoft’s next Patch Tuesday is August 11, 2026. It follows a record-setting July security update cycle that addressed hundreds of vulnerabilities, including flaws reported as exploited in the wild in SharePoint Server and Active Directory Federation Services. Microsoft has also noted that AI-assisted discovery is helping uncover more issues, which can mean larger security update releases over time.

What it means for you

Patching needs an owner, a cadence, and a way to confirm nothing critical slipped through, especially for Microsoft infrastructure that still runs on-premises.

How Covenant helps

Fortify tightens the Microsoft controls attackers target first, while Always-On IT Operations keeps patching on schedule and verified.

Sources: Microsoft Security Update Guide, Microsoft MSRC note on Patch Tuesday, and BleepingComputer July 2026 Patch Tuesday coverage.

08
Identity & phishing

A phishing wave aimed straight at Microsoft 365 sessions.

Microsoft 365 phishing is increasingly focused on stealing sessions and consent, not just passwords. Adversary-in-the-middle phishing, device-code phishing, and OAuth consent tricks can all lead to the same outcome: a user completes what looks like a real sign-in flow, and the attacker walks away with access.

What it means for you

This is how account takeover, invoice fraud, mailbox monitoring, and payment redirection begin. MFA still matters, but these attacks are built to slip around weaker forms of MFA or trusted sign-in flows.

How Covenant helps

A Microsoft 365 Secure Score Assessment finds the gaps these attacks exploit, and Fortify helps close them in practical stages.

Sources: FBI IC3 Kali365 PSA and DomainTools research on Microsoft 365 session hijacking.

09
Identity

The FBI warning is simple: attackers want the token, not the password.

The FBI is warning about Kali365, a phishing-as-a-service platform first seen in April 2026. Instead of intercepting a password, Kali365 can trick users into authorizing a Microsoft 365 session through a legitimate Microsoft device-code flow. The attacker captures OAuth access and refresh tokens, then accesses Outlook, Teams, and OneDrive without completing another MFA challenge.

What it means for you

MFA is essential, but it is not the finish line. Session theft is why Conditional Access, device-code flow controls, risky sign-in review, and token revocation procedures matter.

How Covenant helps

A Microsoft 365 Secure Score Assessment surfaces the session-theft gaps, and Fortify closes them in a practical order.

Source: FBI IC3: Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens.

The bigger picture

Wouldn’t it be better if staying current on Microsoft, security, and AI did not mean doing the homework yourself every week? That is the point of this series. Covenant watches the changes so your team can spend attention on the work only you can do.

Two threads run through this week: Microsoft keeps putting more capability inside the licenses you already hold, and attackers keep aiming at the sign-in that unlocks all of it. Both point to the same next step: a clear baseline of what you own, what is turned on, what is exposed, and what to handle before the next renewal, deadline, or AI rollout.

Related Covenant solutions

Microsoft 365 Tenant Optimization Review

Right-size licensing, reduce waste, and find included Microsoft features you may not be using.

Explore tenant optimization

Microsoft 365 Secure Score Assessment

Benchmark your Microsoft 365 security controls and prioritize the gaps that matter most.

Explore Secure Score

Fortify Microsoft Cyber Hardening

Harden identity, devices, data protection, monitoring, and AI readiness in practical stages.

Explore Fortify

Want a second set of eyes on your Microsoft, security, and AI readiness?

Book time with Covenant. We will help you understand what changed, what matters, and where to start.

Covenant Technology Solutions | Microsoft-first. Security-first. Human.

Scroll to Top