Augmentt Blogs

Expert analysis and practical guides for navigating Microsoft 365 and the evolving world of cybersecurity. Your go-to hub for staying secure and efficient in the cloud.

Augmentt now manages Microsoft Purview, SharePoint and OneDrive sharing, and Microsoft Teams policy across every client tenant you have connected. That includes DLP for Microsoft 365 Copilot. All of it is live today.

  • Microsoft Purview. Verify DLP policies and sensitivity labels across every tenant, including DLP for Microsoft 365 Copilot, and deploy a baseline where a tenant has none.
  • SharePoint and OneDrive. Audit sharing controls against the CIS Microsoft 365 Benchmark on every tenant and remediate a loose setting in a click.
  • Microsoft Teams. Manage meetings, messaging, app permissions, channels and external access, with the org-wide security settings on one screen.

That is three more Microsoft 365 workloads managed the way your team already manages Conditional Access and Intune in Augmentt. Same tenant connections and the same permission model, so there is nothing new to onboard.

The question your clients started asking

Your clients are turning on Microsoft 365 Copilot. Some of them told you first. Some of them did not. Either way the question lands on your desk within a few weeks. Is our data safe with AI?

It is a fair question and a hard one to answer. Copilot is a very capable search and retrieval engine, and the first place it looks is whatever is sitting in SharePoint and OneDrive. If that content was never classified and no data loss prevention policy is in place, Copilot will surface things to people who were never meant to see them, and it will do it fast.

Answering that across a book of business has meant opening one client’s Purview portal, checking, closing it, and opening the next one. No screen existed that could tell you which of your clients had data protection turned on.

Microsoft left this one open

Microsoft 365 Lighthouse was supposed to be the multi-tenant view for partners. It does a reasonable job on identity and threat protection. It does not reach Microsoft Purview, and it does not reach Teams policy.

So two of the three areas your clients ask about most, Purview DLP and Teams policy, have had no cross-tenant tooling behind them at all. The third, SharePoint and OneDrive sharing, has meant checking each tenant by hand.

The defaults do not help. Data protection ships turned off. Collaboration ships wide open, with external federation on, guest access broad, and anyone able to create a team. A client does not have to make a mistake to be exposed. They only have to leave things alone.

What shipped today

Microsoft Purview, including Copilot. Verify whether DLP policies are enabled in every tenant, whether that protection extends into Teams, and whether sensitivity label policies are published. DLP for Microsoft 365 Copilot is part of the DLP policies you manage here. Where a tenant has nothing, deploy a baseline data-protection configuration from Augmentt instead of sending a technician into the client’s Purview portal.

A baseline gets a tenant to a sane starting point. DLP and labeling still need tuning to each organization’s own data, so the part that pays off first is knowing where all of your clients stand and being able to show it.

SharePoint and OneDrive sharing. Augmentt audits the sharing controls against the CIS Microsoft 365 Benchmark on every tenant. External and guest sharing scope, link-sharing defaults, trusted-domain and security-group allowlists, modern authentication, Azure AD B2B integration, and blocking downloads of malware-infected files. Where the control is a setting, fix it from Augmentt in a click. Where it needs a curated list of approved domains or security groups, manage that list here too. If a client loosens something later, you find out.

Microsoft Teams policy. Teams is where client collaboration happens, and it has become a real attack surface, with external users used to phish and socially engineer staff. Manage the policies that shape how Teams behaves: meetings, messaging, app permissions and setup, channels, and external access. View a tenant’s policies, adjust them, assign them to the right users or groups, and create or remove policies without leaving Augmentt. A consolidated settings page puts the org-wide controls that matter most for security on one screen with a single save: guest access, external federation, guest meeting and messaging, and who can create teams.

Why the standard behind it matters

Every check maps back to the CIS Microsoft 365 Benchmark, alongside the HIPAA, CMMC, NIST CSF and Essential Eight mappings already in Augmentt. That matters for two conversations you are going to have.

The first is with an auditor or an insurer. When someone asks for evidence of a control, the answer comes from the same place your team configured it. There is no parallel spreadsheet to keep, and no gap between what was set and what actually gets reported.

The second is about licensing. Some of these controls need premium Microsoft licensing, and Augmentt shows which ones a client’s current licensing covers. So when you tell a client they need Business Premium, you can point at the exact control they do not have today. Most partners already have a portion of their base on premium and get value from this on day one. For the rest, you have something concrete to put in front of them.

Available today

SharePoint and OneDrive sharing controls, Purview DLP and sensitivity labels including Copilot, and Teams policy management are live for every Augmentt partner as of today, across every tenant you have connected. The full control list and the setup steps are in the Help Center.

See it on your own tenants. Start a trial, or book time with our team and we will walk your environment with you.

A client calls because a guest joined a Teams meeting and started sharing their screen when they shouldn’t have been able to. You go looking for the setting, and it’s buried in the Teams admin center for that one tenant. You fix it there, then remember the other nineteen tenants are probably configured the same way, because nobody ever went back and standardized it. So you start clicking through each one by hand.

That’s the kind of work this release is aimed at. Here’s what shipped.

Standardize Microsoft Teams Across Every Tenant, From One Screen

Teams policies and settings are live in Secure Autopilot. You can now see and manage the Teams configuration that actually drives risk, guest access, external federation, meeting permissions, messaging permissions, without opening the Teams admin center for each client separately.

Augmentt Teams Settings screen showing guest access, external federation, and guest meeting and messaging permissions for a client tenant

Alongside settings, you get Teams policies: Meeting, Messaging, Channels, and External access. Build a policy once as a template or baseline, then push it to every client the same way you already do with Conditional Access and Intune. No more recreating the same meeting policy from scratch for the fifteenth time.

Augmentt Teams Policies list showing counts for Meeting, Messaging, Channels, and External access policies across a tenant

And when a client needs something adjusted on the spot, you don’t have to redeploy an entire policy. Inline edit lets you open a policy and change the specific setting live, right from the Augmentt portal.

Augmentt inline edit view of a Teams meeting policy, showing toggles for meeting scheduling, join and lobby settings

Purview Gets Broader DLP Coverage, Plus Retention and Sensitivity Labels

Two weeks ago we shipped Data Loss Prevention policy support. This release extends it. Augmentt now covers additional DLP policy locations, including Copilot, Foundry, Power BI, Managed Cloud Apps, and Inline Web Traffic, so the policy you build accounts for where data actually moves through a client’s tenant now, not just where it moved a year ago.

Retention Policies are here too. Apply retention across Exchange, SharePoint, OneDrive, Teams, and Groups, so a client’s data lifecycle rules are consistent everywhere instead of configured piecemeal per workload.

Sensitivity Labels round it out. Classify and protect data so you control what users, devices, and AI tools can actually access, and how that data can be used once they have it. As Copilot and other AI tools get pointed at client tenants, that label is doing real work.

Augmentt Purview Data Loss Prevention policy list, showing policy name, priority, mode, and sync status for a client tenant

Two New Checks Round Out Email Posture Coverage

Two new security checks joined the posture library this release: inbound anti-spam policies that don’t contain allowed domains, and outbound anti-spam message limits that aren’t in place. Both are common gaps and both show up in the same posture view you’re already using.

Defender EOP: Fix the Check, Right From the Recommendation

Augmentt has supported templating, deployment, and standardization of Defender EOP policies for a while now. This release adds per-security-check configuration on top of it.

Instead of jumping into Microsoft’s admin center to figure out which setting a failing check actually wants, you can now edit the existing policy directly from the check itself, with the recommended settings already populated, through a short wizard flow. That covers all 34 Defender EOP checks Augmentt tracks against Secure Score.

Augmentt Configure tab for a Defender EOP posture check, showing a recommended fix and a choice between editing an existing policy or creating a new one

Where to Find It

Teams settings and policies are under Secure > Teams. The expanded Purview coverage, DLP, Retention, and Sensitivity Labels, is under Secure > Purview. The two new anti-spam checks and the Defender EOP Configure tab show up right where you already review posture, under Secure > Security Posture, on the check itself.

FAQ

What’s the difference between Teams settings and Teams policies in Augmentt?

Settings cover the tenant-wide controls, guest access, external federation, and guest meeting and messaging permissions. Policies are the Meeting, Messaging, Channels, and External access policies you build as templates or baselines and deploy to specific groups of users, then edit inline when something needs a quick change.

Does the new Purview DLP coverage include Copilot?

Yes. This release adds DLP policy coverage for Copilot and Foundry, along with Power BI, Managed Cloud Apps, and Inline Web Traffic locations, on top of the DLP support Augmentt shipped two weeks prior.

How many Defender EOP checks can I now fix through the Configure tab?

34. Each one supports per-security-check configuration, so you can apply the recommended fix to an existing policy or create a new one without leaving the check.

Do I need to rebuild my Defender EOP policies to use the new configuration option?

No. The Configure tab edits your existing policies with the recommended settings needed to satisfy the Secure Score recommendation behind the check. You’re not starting over.

Where do the two new anti-spam checks show up?

Alongside your existing checks in Security Posture: one flags inbound anti-spam policies missing allowed domains, the other flags outbound anti-spam policies without message limits in place.

Photo by Roman Kraft on Unsplash

August was quiet on licensing and identity, but it brought a SharePoint Server patch every on-prem admin needs to act on, a heavy round of Copilot changes with real governance implications, and a clear pattern across Defender: Microsoft is building security controls around AI agents before they become the next unmanaged risk category. Here’s what matters if you’re managing Microsoft 365 across multiple tenants.

Intune

Samsung Knox E-FOTA firmware management for Android Enterprise (week of July 27)

Intune now integrates with Samsung Knox E-FOTA to manage firmware updates for corporate-owned Samsung devices from the admin center, letting you control which firmware versions deploy, schedule updates around a client’s business hours, and push them without user interaction, useful once you’re managing firmware across a large Android fleet spread over several tenants.

New Windows settings catalog entries (week of July 27)

Camera behavior, Keyboard Filter, WSL, OneDrive folder naming, and Edge 148/149 policies are now manageable through the settings catalog, and since none require a new profile type, you can fold them into existing baselines instead of building tenant-by-tenant configuration profiles, the kind of standardization Intune Autopilot is built to apply across every client at once.

Regional Microsoft Store app support (week of July 27)

Admins can now target region-specific Microsoft Store catalogs when deploying apps, closing a gap for multi-regional clients who previously couldn’t get apps outside the US catalog without sideloading.

Custom compliance settings for macOS (week of July 27)

Script- and JSON-based custom compliance checks, already available for Windows and Linux, now work on macOS too, so you can run one compliance framework across every platform in a tenant instead of a Windows-only setup plus manual Mac checks.

Controlled Configuration for Microsoft Defender antivirus, preview (week of July 27)

Defender antivirus settings managed through Intune can now override Group Policy, Configuration Manager, and local scripts, which in hybrid-managed environments stops a leftover GPO from silently overriding a setting you thought was locked in.

Entra ID

No updates worth noting this month.

Defender

Vulnerability assessment for Microsoft Store applications, preview (August)

Defender for Endpoint now surfaces vulnerabilities in Microsoft Store apps, including Teams, Firefox, WhatsApp, Slack, and Dropbox, with file paths and version detail, giving you visibility into consumer-grade apps that land on corporate devices whether or not you sanctioned them.

Defender for Endpoint macOS build 101.26062.0011, GA (August)

A new generally available macOS build shipped with a set of fixes and enhancements. Routine, schedule it into your normal Mac patch cadence.

AI agent posture risk in Microsoft Defender, preview (July)

Defender now scores posture risk for enterprise and locally discovered AI agents based on configuration, access, runtime activity, and active alerts, giving you a place to catch a client running an unsanctioned AI agent and prioritize it for remediation instead of it getting buried in a general alert feed.

Domain investigation page, GA (July)

A centralized view of Active Directory domain security, deployment health, service accounts, sensitive entities, group policies, and trust relationships, useful for pulling together AD domain posture across a client’s infrastructure in one screen instead of piecing it together manually.

Threat detection and real-time protection for Microsoft Agent 365 agents (July)

Defender now analyzes runtime signals from AI agent tool usage and can allow or block interactions with MCP tooling servers in real time. Agentic AI is quickly becoming a standard part of the threat surface you’re expected to monitor, worth getting ahead of before a client asks if you’re covering it, and the kind of baseline monitoring Secure Autopilot helps you keep consistent across every tenant.

Licensing

No updates worth noting this month.

Purview

Auto-labeling policy simulation mode (August)

You can now run an auto-labeling policy in simulation mode to preview what it would label before enforcing it, reviewing match results and source distribution first, a safe way to validate a policy against a client’s real content instead of discovering it over- or under-labels after enforcement is already live.

Auto-labeling policy Insights tab (August)

A new tab on the policy details page reports performance metrics for auto-labeling policies in both simulation and enforcement mode, giving you quick, concrete evidence to show a client that a labeling policy is doing what you told them it would.

Teams

Nothing landed in the Desktop & Web changelog this August. The most recent additions from July, a Meeting Recaps app and a fix that makes Teams for web remember sign-in preferences across sessions, don’t require any action.

Copilot

August was a heavy month for Copilot. A few items below are worth a governance review, not just a features read.

ServiceNow connectors support role-based permissions (August 11)

ServiceNow Knowledge and Catalog connectors now enforce access based on user roles like admin or knowledge manager, instead of user criteria alone, worth an audit of any client’s ServiceNow connector configuration to confirm permissions are mapped correctly rather than assuming the old setup still behaves the same way.

SharePoint Authoritative Sites (August 11)

Admins can designate specific SharePoint sites as authoritative so Copilot prioritizes trusted content, like company policy and official news, in search results, a concrete lever for improving Copilot answer quality in a client tenant and worth adding to your Copilot rollout checklist.

Copilot in PowerPoint can reference web sources (August 11)

When generating a presentation, Copilot can now pull in and cite current web sources, which means content from outside the tenant boundary can end up in a client deliverable. Worth checking against any client’s DLP or content filtering policy before it reaches end users.

Consumption Dashboard tracks Copilot credit usage (August 11)

Viva Insights now shows Copilot credit consumption for Cowork and Work IQ API services, visible to managers with five or more reports, Insights analysts, and Global admins, the first real per-tenant visibility into Copilot usage costs and useful the next time a client asks why their AI bill went up.

Outlook

Go to Folder dialog and a fourth message list column (August 14)

New Outlook for Windows added a Go to Folder dialog (Ctrl+Y or mailbox context menu) and an extra content column in the message list when sorting is applied. Minor, but worth mentioning to power users who ask about navigation.

Inbox rules support “mentions you” and external sender conditions (August 7)

New rule conditions for messages that mention you directly or come from outside the organization give clients a genuinely useful control for cutting down on missed messages, and double as light phishing awareness.

Bulk contact deletion, up to 100 at a time (August 7)

Contacts can now be deleted in bulk instead of one at a time, a small but real time saver for your technicians cleaning up after offboarding rounds.

OneDrive & SharePoint

SharePoint Server Subscription Edition security update, KB5002893 (August 11)

Patches SharePoint Server Subscription Edition (build 16.0.19725.20522) against 26 CVEs, including remote code execution, information disclosure, spoofing, security feature bypass, and elevation of privilege. Also disables file-backed Business Data Connectivity model imports by default. Environments running SharePoint Workflow Manager need KB5002799 installed first. This is the must-do item this month: any client still running on-premises SharePoint Server needs this patched now, not on the next routine cycle.

OneDrive sync client for Windows, build 26.119.0622.0003 (July 10)

Fixed a bug where the sync client checked Folder Shortcuts against the wrong root path when validating max path length, which should reduce false “path too long” errors and the support tickets that come with them. Nothing else notable has shipped since.

The bottom line

August didn’t bring the licensing or identity shake-ups we’ve seen in past months, but the pattern worth watching is Defender and Copilot building governance and security tooling around AI agents ahead of them becoming widespread in customer tenants. Add a mandatory SharePoint Server patch and two quiet Purview improvements for safely testing labeling policies, and there’s enough here to work into next month’s client reviews even without a headline feature launch.

If you’d rather not track all of this manually every month, you can start a free trial of Augmentt and see how much of it runs on autopilot instead.

FAQ

What is the most urgent Microsoft 365 update for MSPs this August?

The SharePoint Server Subscription Edition security update (KB5002893), released August 11, patches 26 CVEs including remote code execution and elevation of privilege vulnerabilities. Any MSP with clients running on-premises SharePoint Server should schedule this immediately rather than waiting for a routine patch cycle.

Did Microsoft Entra ID or licensing change this month?

No. August was quiet on both fronts, with no notable Entra ID or CSP licensing changes to report.

What’s new with Microsoft Defender for AI agents?

Defender added posture risk assessment for enterprise and local AI agents, runtime threat detection for Microsoft Agent 365 agents, and real-time protection that can allow or block interactions with MCP tooling servers. Together these give security teams visibility into AI agents that might otherwise go unmanaged inside a tenant.

Should MSPs be concerned about Copilot in PowerPoint referencing web sources?

It’s worth reviewing rather than being alarmed by. The feature lets Copilot pull in outside content when building a presentation, which can conflict with a client’s DLP or content filtering policies if those aren’t already accounting for it. Confirm those policies before the feature reaches end users.

What changed with Purview auto-labeling this month?

Purview added simulation mode for auto-labeling policies, letting admins preview what a policy would label before enforcing it, plus a new Insights tab reporting on policy performance. Both make it easier to validate a labeling policy against real tenant content before turning it on.

Is there anything MSPs need to do about the new Copilot Consumption Dashboard?

Not urgently. The dashboard, in Viva Insights, gives managers and admins visibility into Copilot credit usage for Cowork and Work IQ API services, useful the next time a client asks why their AI costs went up.

Did Teams get any updates MSPs need to act on this month?

No significant changes landed in the Teams Desktop & Web changelog in August. The Meeting Recaps app and improved web sign-in persistence, both from July, are worth knowing about but don’t change how you manage tenants.

Where can MSPs find these updates directly from Microsoft?

Microsoft publishes ongoing changelogs for each product: the Intune what’s new page, the Defender for Endpoint and Defender XDR what’s new pages, the Purview what’s new page, Microsoft 365 Copilot release notes, the New Outlook and Outlook Mobile release notes, and the SharePoint/OneDrive sync release notes. Checking these directly is useful between monthly roundups if something urgent ships mid-month.

Photo credit: Zulfugar Karimov on Unsplash

Augmentt updates August 2026

You find one setting turned off in a client tenant. You check the next tenant and it’s off there too. By the time you’ve worked through the list, it’s Tuesday.

That’s the work this release is aimed at. Here’s what shipped.

Fix a Failing Check Across Every Tenant From One Screen

The old version of this job: find the misconfigured setting, open the tenant, fix it, repeat. Fifteen clients, fifteen rounds.

From the All Companies Compliance Audit, open the Fix action on a check.

Augmentt will then line up every tenant currently failing it. Review the affected tenants, apply the recommended configuration, and it deploys to all of them in one go. You get a per-customer result so you can see exactly which tenants the change landed on, and every change is written to the audit log.

AI Risk Report Is Now Generally Available

Your clients are turning on Copilot whether or not they asked you first. The question that follows is what it can see.

The AI Risk Report is out of beta and available to every Secure user, under the Reports menu next to the Threat Report. It covers Copilot deployment readiness, data exposure, identity and access, and third-party shadow IT when the tenant is licensed for Discover. The report also explains why each recommendation matters, so it holds up in front of a client.

Two sections worth opening first.

AI Risk Report SharePoint site inventory showing ownership, sharing level and application access per site

SharePoint site inventory and sharing settings. Copilot surfaces what a user already has access to. Oversharing nobody noticed for three years becomes obvious the day Copilot turns on. You get the site-level view of what’s shared and how.

Sensitivity labels and data loss prevention. A label inventory sitting next to a DLP policy inventory, with counts for labels deployed, DLP policies in enforcement, and whether the tenant has a default label set. AI exposure comes down to what’s labeled and what isn’t, so this is the section to watch.

AI Risk Report third-party and AI ecosystem panel showing unsanctioned AI apps detected across the tenant

Shadow AI shows up as unsanctioned applications and websites. Pair Secure with Discover for the wider view of where client data is actually going.

Purview DLP Policies

Under Secure > Purview > Data Loss Prevention, Augmentt now pulls and displays a tenant’s DLP policies, so you can see them without opening the Purview portal.

Augmentt Purview Data Loss Prevention page listing a tenantโ€™s DLP policies with mode and sync status

Turn a policy into a sanitized, reusable template and deploy it across as many tenants as you want. Same standardize-and-roll-out pattern you already use elsewhere in Augmentt.

DLP policies in Augmentt now support Microsoft 365 Copilot and Microsoft Foundry as policy locations, so as clients turn on AI you can extend their data-loss protection to cover it.

Purview access sits behind its own dedicated permission on your System Users, separate from the Secure permission, so you decide who on the team works with this data.

Break-Glass Accounts Stop Reading as Failures

Every tenant should have an emergency break-glass account, preferably two, kept aside so a Conditional Access misfire can never lock you out entirely. Augmentt had no way of knowing which account that was, so it showed up in the MFA report as a problem to chase.

A new posture check lets you define and validate a tenant’s emergency accounts. Once defined, they carry a distinct Break Glass status in the Admin MFA and User MFA checks and are treated as compliant, the same way a sign-in-blocked account already is, across the pie chart, the details table, and filtering.

More Compliance Checks, Plus SharePoint

SharePoint policies are now supported, which completes coverage of the CIS M365 controls.

New posture checks, all with a Configure action:

  • MailTips enabled for end users (6.5.2), so people see the in-compose warning when sending externally or to a large audience
  • User owned apps and services restricted (1.3.4), covering Office Store access and starting trials on behalf of the organization
  • Internal phishing protection for Microsoft Forms (1.3.5), so a tenant that had this quietly switched off is easy to spot
  • Smart Lockout Threshold and Smart Lockout Duration, both settable inside Augmentt on the tenant’s Entra password-protection settings
  • Block the device code sign-in flow (5.2.2.12), a path attackers like to abuse, remediated by deploying our Conditional Access template from the check’s Configure tab
  • Sign-in frequency for Intune enrollment (5.2.2.11), which forces re-authentication at enrollment and closes the gap that lets someone enroll a rogue device on a stolen session
  • Exchange Online connection filter, two checks: confirm the IP allow list isn’t waving mail past your spam checks (2.1.12), and that the connection filter safe list is off (2.1.13)
  • Security Defaults monitoring, two checks reading the same signal with opposite logic, so you can confirm Security Defaults is on where a tenant relies on it as a baseline, or off where you’ve moved that tenant onto Conditional Access

Smaller Changes You Asked For

Set a check’s status yourself. Mark a posture check Planned, Risk Accepted, Resolved by 3rd Party, or Alternate Mitigation, or hand it back to Augmentt’s evaluated status at any time. Works across all postures and updates the Microsoft Secure Score where applicable.

Augmentt Resolve Check dialog setting a posture check status to Planned with status details

Add a note to any check. Record context and evidence on a posture check as free text, stored separately from the status. On export you choose whether notes come along, so you control what a customer sees.

Notes tab on an Augmentt posture check showing a dated comment added by a technician

Show only the columns you want. Pick which columns appear in the audit table, and that choice carries through to the PDF, CSV, and Excel exports. Hand a client a clean report with only the data you want on it.

Augmentt audit table column selector with checkboxes for status details, categories, rationale and notes

Better Conditional Access deployment. Inside the Compliance Audit Configure experience you can now apply a fresh policy to remediate a control, or edit a closely matching policy instead of creating a duplicate.

Augmentt Configure tab showing existing Conditional Access policies with a best match and per-requirement pass or fail

Alphabetical sorting. Some lists weren’t sorted. They are now. Tell us if you spot another.

Minimum license requirement is back. You asked for it, it’s back.

Where to Find It

Everything above is live. AI Risk Report under Reports, DLP under Secure > Purview, the rest inside Compliance Audit.

Cover Photo by Christian Wiediger on Unsplash

msp offboarding guide

Most MSPs have a documented onboarding process that a junior technician could follow without much guidance. Far fewer have anything close to that for offboarding, and that gap is usually where the risk quietly builds up.

Offboarding tends to get treated as the tail end of an HR event, something that gets wrapped up with a quick IT ticket once someone’s last day arrives. In practice, it functions as a security control, and an important one. An account that stays active a day longer than it should, a shared mailbox nobody remembered to lock down, or a SaaS login that was never connected to single sign-on all amount to the same thing: a door that stays open after the person who used it has already left the building. For an MSP managing dozens or hundreds of client tenants, that risk isn’t a one-time event. It resurfaces every time any employee leaves any client, usually on a schedule the MSP doesn’t control and sometimes doesn’t even hear about until well after the fact.

This playbook walks through what a complete offboarding process actually needs to cover, the places where MSPs most often lose track of a step, and how to turn offboarding from a reactive scramble into a standardized service that runs the same way across every client, no matter which technician happens to be on the ticket.

What Is IT Offboarding?

IT offboarding is the process of systematically removing a departing user’s access to every system, application, and data source they could reach while employed, including accounts, devices, licenses, shared resources, and any SaaS tool tied to their identity, while still preserving the business continuity of their email, files, and any work in progress that needs to be handed off. Done well, it looks like a coordinated checklist that gets executed the moment a departure takes effect. Done poorly, it looks like a handful of steps someone half-remembers, scattered across whichever administrator happened to pick up the ticket that day.

For an MSP, offboarding is never really a single process. It’s the same set of obligations repeated across every client tenant, and each of those tenants comes with its own licensing setup, its own shared mailboxes, its own shadow IT footprint, and its own tolerance for delay.

Why Offboarding Carries More Risk Than It Looks Like

The research on this is fairly consistent. Industry surveys place offboarding among the highest-risk moments in the identity lifecycle. A large majority of IT professionals name it as a critical point of cybersecurity exposure, and a majority of organizations report having experienced a breach connected to former-employee access at some point (Newployee, 2026). Gartner-cited research found that only 44% of companies manage to revoke all of a departing employee’s access within 24 hours, which means most organizations are running exposed for longer than they probably assume (CheckFlow, 2026). Cyberhaven’s analysis of exfiltration activity also found a 720% spike in risky data movement in the days immediately before layoffs are announced, a window that most companies aren’t monitoring at all (Cyberhaven, cited in CheckFlow).

There’s also a scale problem layered on top of that timing problem. The average employee touches close to 30 different SaaS applications, and the average organization now manages several hundred SaaS tools across its business (CheckFlow, 2026). Many of those tools were never provisioned through IT, were never connected to single sign-on, and never show up on a standard deprovisioning checklist as a result. Turning off someone’s primary work identity does nothing to close an app they signed up for directly with a personal card, which is exactly why it keeps slipping through.

For an MSP, that scale problem multiplies across every client on the roster. A missed step at one client isn’t an isolated incident so much as a preview of a pattern that will eventually show up everywhere, often at the one moment it matters most.

The Core Offboarding Checklist

A complete offboarding process runs in phases rather than as a single action. Jumping straight to “disable the account” and calling it done is usually how the gaps described above happen in the first place.

Immediate, day-zero actions:

  1. Block sign-in on the primary identity so no new session can start, and force sign-out of any devices or apps where the user is already authenticated.
  2. Reset the account password as a secondary containment step, particularly if the departure is involuntary or there’s any concern that the credentials could still be shared or guessed.
  3. Revoke or re-register MFA methods so a former employee’s phone or authenticator app can’t later be used to approve a sign-in.
  4. Unassign the licenses tied to the user, both to reclaim the cost and to shrink what the account could still reach even if it were somehow reactivated.

Continuity and communication:

  1. Decide what happens to the mailbox, whether that means converting it to a shared mailbox, forwarding mail to a manager, or setting up an out-of-office auto-reply. The right choice usually depends on the role and on how abruptly the person left.
  2. Remove any delegate access other staff had into the departing user’s mailbox or calendar, and address any shared mailbox access the user themselves held.
  3. Hide the user from the Global Address List once continuity is handled, so they stop surfacing in directory lookups and distribution list expansions without disabling the mailbox outright.

Cleanup and audit:

  1. Remove the user from security groups and distribution lists so they lose downstream access and stop receiving internal communications they no longer need.
  2. Audit for shadow IT, meaning any SaaS accounts the user created outside of single sign-on that IT never provisioned and that won’t automatically lose access when the primary identity is disabled.
  3. Recover any company-owned devices and confirm that locally cached data or credentials have been wiped.
  4. Log every action taken, along with a timestamp, so there’s a defensible record if the departure is ever questioned by the client, an insurer, or a regulator down the line.

The order genuinely matters here. Access-blocking steps should happen first and immediately, while continuity and cleanup steps can follow within the same session. Neither should become the reason containment gets delayed.

Where MSPs Typically Lose the Thread

A handful of patterns tend to show up again and again in accounts of offboarding failures, and each one is worth naming because each one is avoidable.

The Friday-afternoon and after-hours gap. Departures rarely happen on a schedule that lines up neatly with a team’s staffing. A termination communicated late on a Friday, with no ticket filed until Monday morning, can leave an account fully live for an entire weekend.

Shadow IT that the primary identity never touched. Disabling someone’s Microsoft 365 or Google Workspace account doesn’t reach a SaaS tool they signed up for directly, especially one that was never brought behind SSO. Those accounts are easy to overlook, and because nobody’s watching them, they’re just as easy to misuse.

Inconsistency across technicians. Without a documented, standardized checklist, the quality of an offboarding depends entirely on which technician picks up the ticket and how much of the process they happen to remember on that particular day. That’s a fairly fragile way to run something that functions as a security control across dozens of clients.

No record of what was actually done. When a client, a cyber insurer, or an auditor eventually asks for proof that a given account was fully offboarded and exactly when, plenty of MSPs don’t have a clean answer ready. A process that isn’t logged isn’t really auditable, and a service that isn’t auditable is a hard thing to sell as a security control.

Turning the Checklist Into a Standardized Service

The fix for all four of those failure modes is more or less the same. Offboarding needs to stop being treated as a one-off ticket and start being treated as a standardized workflow that runs the same way, with the same steps, on every tenant, regardless of who happens to be on shift that day.

In practice, that means defining the offboarding defaults once, deciding which security actions run automatically, how mailbox continuity is handled by default, and what “done” actually looks like, and then applying that same template across every client instead of reinventing the checklist every time a new ticket comes in. It also means closing the timing gap. A process that can be scheduled in advance, given that an employee’s last day is usually known well ahead of time, removes the dependency on someone being awake and logged in at exactly the right moment.

This is roughly where Augmentt fits into an MSP’s offboarding practice.

Augmentt is a multi-tenant Microsoft 365 security and management platform built specifically for MSPs, and its Engage Autopilot module is built around this exact workflow. Engage lets a technician offboard a user across a Microsoft 365 or Google Workspace tenant from a single screen. That includes unassigning licenses, resetting the password, forcing sign-out of all applications, blocking sign-in, removing delegate access, hiding the user from the Global Address List, converting the mailbox to shared, setting up forwarding or an out-of-office reply, and removing shared mailbox access, all without having to jump between the Microsoft admin center, Exchange, and Entra ID separately for each individual action. For MSPs on an Engage Autopilot license, that same offboarding workflow can also be scheduled ahead of time for a specific date and time, with optional notifications on success or failure, so a known departure date doesn’t rely on anyone remembering to log in and trigger it manually. Engage also supports co-managed setups, where a client’s own staff can be given a limited and audited set of onboarding and offboarding actions to run themselves, which reduces ticket volume for the MSP without handing over full administrative access.

Offboarding a single Microsoft 365 or Google Workspace identity is necessary but isn’t quite sufficient on its own, and that’s where the shadow IT problem mentioned earlier comes back into the picture. Augmentt’s Discover module maintains visibility into the SaaS applications actually in use across a client’s environment, drawing on a database of more than 22,000 applications, and it flags risky or unmanaged app usage that wouldn’t be caught by looking at the primary directory alone. Pairing that visibility with the offboarding workflow in Engage gives a technician a fuller picture of what a departing user might still be able to reach beyond the tenant itself.

The audit-trail problem is handled by design rather than as an afterthought too. Actions taken through Engage are logged, which gives MSPs a record to point to whenever a client, cyber insurer, or compliance reviewer asks whether a particular offboarding was completed and when. Augmentt is also SOC 2 Type II and GDPR compliant, which tends to matter for MSPs whose clients operate in regulated or compliance-sensitive industries and need that kind of assurance about the tools touching their tenants.

Building Your Own Offboarding Playbook

Whether or not automation tooling is part of the picture yet, most MSPs can tighten their offboarding practice with roughly the same three moves.

Document the default. Write down exactly which actions happen on every offboarding, in what order, and who’s responsible for triggering each one. The goal is a checklist that a junior technician can execute correctly without needing to ask a senior engineer what might have been missed.

Remove the timing dependency. Wherever possible, separate the question of when an offboarding should happen from the question of when a person remembers to do it. A known last day should translate into a pre-scheduled action rather than a note left on someone’s desk.

Close the loop with an audit trail. Every offboarding should leave behind a record of what was done, when, and by whom, so the MSP can answer for it later without having to reconstruct the details from memory or old ticket notes.

Offboarding will probably never be the flashiest part of an MSP’s service lineup, but it’s one of the few areas where a single missed step can carry an outsized, and entirely avoidable, cost. A documented, standardized, and where possible automated offboarding playbook turns that risk into just another routine part of the service, which is really where it belongs.

FAQ

What is the difference between IT offboarding and HR offboarding?

HR offboarding covers the people side of a departure, including exit interviews, final pay, benefits, and paperwork. IT offboarding covers the technical side: revoking access to accounts, applications, and devices so a former employee can no longer reach company systems or data. The two need to be coordinated closely, since IT offboarding usually can’t fully begin until HR confirms the departure and its effective date.

How quickly should access be revoked after an employee leaves?

Immediate access-blocking steps, such as disabling sign-in, forcing sign-out, and resetting the password, should happen right when the departure takes effect rather than waiting for a ticket to be manually picked up. Industry data shows fewer than half of organizations manage to revoke all access within 24 hours, which is precisely the gap a documented, scheduled offboarding process is meant to close.

What is shadow IT and why does it matter for offboarding?

Shadow IT refers to SaaS applications or accounts that employees set up on their own, outside of IT’s visibility and outside single sign-on. Disabling a user’s primary Microsoft 365 or Google Workspace identity does not remove access to these tools, which is why a shadow IT audit needs to be part of a complete offboarding checklist rather than an afterthought.

Can offboarding be scheduled in advance?

Yes. Since a departure date is usually known well ahead of time, offboarding actions, including license removal, mailbox handling, and account deactivation, can be scheduled to execute automatically at a set date and time instead of requiring a technician to remember and manually trigger each step. Augmentt’s Engage Autopilot supports this for Microsoft 365 tenants through its scheduled offboarding workflow.

How can MSPs standardize offboarding across many clients at once?

By defining a single offboarding template, meaning the exact set of actions applied by default in the exact same order, and then running that same template on every client tenant instead of leaving the process to individual technician memory. A multi-tenant platform that lets technicians execute and schedule that workflow from one interface, across every client, is what makes that kind of standardization realistic at scale

Cover Photo by Vitaly Gariev on Unsplash

Compliance used to be something MSPs worried about only when a healthcare or financial services client asked for it. That’s no longer the case. Cyber insurance carriers are demanding proof of security controls before they’ll issue or renew a policy. State privacy laws are spreading well beyond California. And clients in construction, manufacturing, and professional services are increasingly asking their MSP the same question: “Can you show me we’re secure?”

For MSPs, compliance frameworks aren’t just a checkbox for regulated clients anymore but are becoming the common language for proving security value across your entire book of business. The challenge is that there are a lot of frameworks, they overlap in confusing ways, and most MSPs don’t have a compliance officer on staff to sort it all out.

This post breaks down the compliance frameworks that matter most for MSPs and their clients, explains how they relate to one another, and shows where Augmentt fits into the picture, especially through its Microsoft 365 security posture and CIS benchmark reporting.

Why compliance frameworks matter for MSPs, not just their clients

A compliance framework is a structured set of security controls and best practices; things like requiring multi-factor authentication, encrypting data at rest, logging administrative activity, or restricting who can access sensitive systems. Frameworks exist so that a business (and its customers, regulators, or insurers) can point to a recognized standard and say, “we followed this.”

For an MSP, frameworks show up in three ways:

  1. Client requirements. A healthcare client needs HIPAA. A defense contractor needs CMMC. A software client’s enterprise customers demand SOC 2. If you manage their IT environment, you’re implicated in whether they pass an audit.
  2. Cyber insurance underwriting. Insurers increasingly use frameworks like the NIST Cybersecurity Framework or CIS Controls as the baseline for what they’ll ask about on an application, and what they’ll use to deny a claim if it wasn’t in place.
  3. Your own differentiation. MSPs that can speak fluently about compliance, and back it up with reporting, win more security-conscious deals and justify higher-margin security services.

The good news: most of these frameworks share a large common core of controls. You don’t need to master ten separate rulebooks โ€” you need to understand the handful that come up most often and recognize how they overlap.

The frameworks MSPs run into most often

NIST Cybersecurity Framework (CSF)

The NIST CSF, maintained by the U.S. National Institute of Standards and Technology, is less a checklist than an organizing structure. Version 2.0 groups activities into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It’s voluntary and not industry-specific, which is exactly why it’s so widely adopted. It works as a common vocabulary that other frameworks (and many cyber insurance questionnaires) map back to.

For MSPs, NIST CSF is often the framework you use to structure a client’s overall security program, even if a more specific framework governs a particular compliance obligation.

CIS Controls and CIS Benchmarks

The Center for Internet Security (CIS) publishes two related things MSPs should know apart: the CIS Critical Security Controls, a prioritized list of 18 safeguards (things like inventory and control of assets, access control management, and continuous vulnerability management), and CIS Benchmarks, which are prescriptive, product-specific configuration guides, including one built specifically for Microsoft 365.

CIS Benchmarks are popular with MSPs because they’re actionable in a way broader frameworks aren’t. Instead of “protect access to systems,” a CIS Benchmark tells you the exact tenant setting to change. Because CIS controls are deliberately cross-mapped to NIST CSF, ISO 27001, PCI DSS, CMMC, HIPAA, and GDPR, hardening a client’s environment to the CIS Microsoft 365 Foundations Benchmark also moves the needle on most other frameworks a client might need.

This is where Augmentt is most directly useful. Augmentt’s security posture checks and MFA reporting are mapped to specific controls in the CIS Microsoft 365 Foundations Benchmark v2.0.0; things like identifying admin accounts without MFA, blocking legacy authentication, monitoring Microsoft Purview audit log status, enforcing idle session timeouts, and alerting on risky sign-ins or role changes outside of Privileged Identity Management. The Security Posture Report shows a Posture Score, flags each check as compliant, partially compliant, or not compliant, and lets you export a branded PDF for a client who doesn’t have Augmentt access, turning a compliance conversation into something you can show, not just describe.

HIPAA

The Health Insurance Portability and Accountability Act governs how healthcare providers, insurers, and their business associates (which can include an MSP) protect patient health information. HIPAA’s Security Rule requires administrative, physical, and technical safeguards; access controls, audit controls, encryption, and breach notification procedures among them.

If you support any healthcare client, you’re very likely a HIPAA “business associate,” which means you need a signed Business Associate Agreement and a genuine security program behind it, not just a promise. Many of the technical safeguards HIPAA requires (access control, audit logging, encryption of data in transit, session timeouts) overlap directly with the CIS Microsoft 365 controls Augmentt already monitors.

SOC 2

SOC 2 is an attestation, not a government regulation. A CPA firm audits a company against the AICPA’s Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy) and issues a report. SOC 2 matters to MSPs in two directions: clients in SaaS and professional services increasingly need a SOC 2 report to win their own enterprise customers, and MSPs themselves are sometimes asked by clients to prove their own SOC 2 compliance, since the MSP has privileged access to client systems.

Notably, Augmentt has undergone its own SOC 2 Type 2 audit as a vendor, giving its MSPs even more peace of mind.

CMMC (Cybersecurity Maturity Model Certification)

CMMC applies to companies in the Department of Defense supply chain, and it’s built on NIST SP 800-171. It has tiered levels of maturity, and unlike some frameworks, third-party or government assessment is required at the higher levels. If you have clients who are defense contractors or subcontractors, CMMC compliance isn’t optional, and the underlying controls (access control, audit and accountability, incident response, configuration management) again overlap heavily with what CIS-aligned Microsoft 365 hardening already covers.

PCI DSS

The Payment Card Industry Data Security Standard applies to any organization that stores, processes, or transmits cardholder data. It’s prescriptive about things like network segmentation, encryption, and access restrictions. MSPs supporting retail, hospitality, or e-commerce clients will run into PCI DSS regularly, particularly around securing the systems and email accounts that touch payment workflows.

ISO/IEC 27001

ISO 27001 is an international standard for information security management systems (ISMS). It’s less common among small and mid-sized MSP clients in North America than SOC 2, but it shows up often with clients that do business internationally or with enterprise customers overseas. Like the others, its control set (access control, cryptography, operations security) overlaps substantially with CIS and NIST.

GDPR and state privacy laws

The EU’s General Data Protection Regulation applies to any organization processing the personal data of EU residents, which catches more MSP clients than people expect, especially those with any European customers, employees, or web traffic. In the U.S., a growing patchwork of state privacy laws (California, Colorado, Virginia, and others) imposes similar obligations around data access, deletion rights, and breach notification. These aren’t security control frameworks in the same technical sense as NIST or CIS, but they create legal requirements around how quickly and thoroughly a client (and their MSP) can respond to a data request or breach, which is where good audit logging and access reporting (the kind Augmentt’s alerting provides) becomes evidence rather than just good practice.

How the frameworks relate to each other

The reason this list feels overwhelming at first is that most MSPs try to treat each framework as a separate project. In practice, the frameworks share a large overlapping core:

Access control and MFA enforcement appear in every single one of them, just under different names โ€” NIST CSF calls it PR.AC, SOC 2 addresses it under CC6.1, HIPAA covers it in the Access Control standard, ISO 27001 handles it in Annex A.9, and CMMC maps it to the AC domain. The same is true of audit logging, encryption, and incident response.

That means the highest-leverage work an MSP can do is harden the common core โ€” strong MFA, tight admin access, audit logging turned on, legacy authentication blocked, DLP and sharing policies configured correctly โ€” and treat framework-specific requirements as the smaller layer on top. This is exactly the approach the CIS Microsoft 365 Foundations Benchmark takes, and it’s why it functions as a practical starting point regardless of which specific framework a given client ultimately needs to satisfy.

Where Augmentt fits

Augmentt isn’t a compliance certification body, and it won’t issue you a HIPAA or SOC 2 attestation. What it does is give MSPs continuous visibility into the Microsoft 365 security controls that sit underneath nearly every framework on this list:

  • Security posture checks mapped directly to the CIS Microsoft 365 Foundations Benchmark v2.0.0, covering MFA enforcement, legacy authentication, conditional access, Purview audit logging, mailbox auditing, DLP policies, Sharepoint and Teams sharing settings, and more.
  • The Security Posture Report, which scores a tenant’s compliance status (compliant, partially compliant, not compliant, resolved, or risk-accepted) against those checks, ties each item to its Microsoft Secure Score impact, and exports as a branded PDF for clients.
  • Alerting on risky sign-ins, role and permission changes, self-service password reset activity, and mail forwarding rule changes โ€” the kind of continuous monitoring that HIPAA, SOC 2, and CMMC all expect to see in place, not just configured once and forgotten.
  • Scheduled reporting, so posture and compliance status can go out to clients automatically on a recurring cadence rather than requiring a manual pull before every QBR.

For an MSP juggling multiple clients with different compliance obligations, that combination โ€” one dashboard mapped to a benchmark that overlaps with nearly every other framework, plus reporting you can hand to a client or auditor โ€” turns compliance from a once-a-year scramble into an ongoing, demonstrable process.

Getting started

If you’re not sure where a given client stands, the fastest starting point is usually the same regardless of which framework they ultimately need to satisfy: run a CIS Microsoft 365 Foundations Benchmark assessment, close the highest-impact gaps (MFA, legacy auth, audit logging, admin role hygiene), and build reporting into your regular client cadence so compliance becomes a running conversation instead of a fire drill. From there, layer in the framework-specific requirements โ€” a signed BAA for HIPAA clients, evidence collection for a SOC 2 audit, NIST 800-171 documentation for CMMC โ€” on top of that hardened baseline.

Compliance will keep getting more complicated as more frameworks and state laws come online. But the underlying security work barely changes. Get the fundamentals right once, and you’re most of the way to satisfying whatever framework comes up next.

Want to check your own clients’ security posture? Try Augmentt for free!

Cover Photo by Jakub ลปerdzicki on Unsplash

Microsoft 365 updates July 2026

July 2026 brings a lighter but no less consequential wave of Microsoft 365 changes: licensing finally catches up with the Copilot promotional push, Entra ships several identity-governance upgrades, and Purview starts locking down AI data flows at the network layer. A few items carry hard dates worth calendaring now.

Intune

Advanced Intune Capabilities Are Rolling Into Microsoft 365 E3 and E5

Microsoft is folding several Intune Suite capabilities directly into Microsoft 365 E3 and E5, no separate add-on required. E3 (via EMS E3) gains Remote Help, Advanced Analytics, and Intune Plan 2 (Microsoft Tunnel for MAM, specialty device management, FOTA updates). E5 adds Endpoint Privilege Management, Enterprise Application Management, and Microsoft Cloud PKI on top of that. Rollout is automatic and gradual, with a 30-day admin center notice before it lands in any given tenant. MSPs should revisit client licensing conversations now โ€” capabilities you may have been quoting as a paid upsell are about to become “already included” for E3/E5 clients, which changes both your pricing story and your renewal risk.

Multi Admin Approval Now Enforces on API Calls Made by Automation

Multi Admin Approval (MAA) previously only gated interactive admin actions; it now also applies to Microsoft Graph API calls made by service principals, scripts, and third-party tools. If a tenant has MAA policies configured, automation lacking the required approval headers will start returning HTTP 403 errors. MSPs running RMM or custom Graph-based automation against MAA-enabled tenants need to update those scripts to the new approval workflow, or use the new Exclusions tab to carve out specific applications before this breaks a client’s automated workflows.

New Android Enterprise Setting Blocks Apps From Exposing Functions to AI Agents

A new settings catalog option, “Block apps from exposing app functions,” lets admins prevent managed apps on corporate-owned Android devices from exposing programmatic actions that on-device AI agents or assistants can invoke. As agentic AI features spread across mobile OSes, MSPs should treat this as a new baseline control worth adding to Android Enterprise configuration profiles, particularly for clients with regulated or sensitive data on managed devices.

Managed Win32 App Content Now Requires HTTPS Delivery

Intune now requires HTTPS for managed Win32 app content delivery. This mainly affects organizations using Microsoft Connected Cache without HTTPS configured on their cache nodes โ€” those clients will silently fall back to CDN delivery, bypassing the cache and increasing internet bandwidth usage. MSPs managing Connected Cache deployments should audit cache node configuration now rather than waiting for a client to notice slower or costlier app deployments.

ChatGPT Added as a Protected App for Intune

ChatGPT is now available as a protected app under Intune’s app protection policy framework, meaning MAM controls (data cut/copy/paste restrictions, save-as blocks, etc.) can be applied to it like other managed apps. With generative AI tools spreading into client environments largely ungoverned, MSPs should treat this as an opportunity to bring at least one major GenAI consumer app under formal data-loss controls.

Entra ID

Microsoft Entra Backup and Recovery Reaches General Availability

Entra Backup and Recovery โ€” daily, Microsoft-managed snapshots of core directory objects (users, groups, apps, service principals, Conditional Access policies, and more) โ€” is now generally available, having been in preview as recently as last month. Tenants with Entra ID P1/P2 get one backup per day retained for 7 days, with diff reports and point-in-time restore. MSPs should formally add this to incident response runbooks now that it’s GA rather than treating it as an optional preview feature.

New Built-In “SOC Identity Responder” Role for Defender-Initiated Containment (Preview)

A new built-in Entra role lets SOC analysts perform identity containment actions โ€” disabling users, revoking sessions, forcing password resets โ€” triggered from Microsoft Defender, without being granted broad directory admin privileges. It supports role-assignable groups and optional PIM just-in-time activation. For MSPs running a SOC or MDR-style service across client tenants, this closes a real gap where analysts previously needed high-privilege roles just to act on an active incident.

AD Group Enforcement Prevents Drift Between Entra and On-Prem AD Groups (Preview)

For hybrid environments using group provisioning to Active Directory, admins can now designate specific AD groups so that changes are only accepted if made through the Entra provisioning service โ€” direct edits made outside Entra are blocked. This is a meaningful control for MSPs managing hybrid identity, where AD group drift is a common source of access-review headaches and audit findings.

BYOD Support for Windows Client Using Entra Registration Reaches GA

Windows BYOD support via Entra-registered (not domain-joined) devices is now generally available, letting users and partners access corporate resources from personal Windows devices via the Private Application traffic profile, including internal guest users. MSPs supporting clients with contractor or BYOD-heavy workforces can now offer a fully supported non-domain-joined access path instead of workarounds.

Conditional Access Gains Dedicated Controls for AI Agent Accounts (Preview)

Conditional Access now supports targeting AI agents’ user accounts directly โ€” scoping policies by custom security attributes, enforcing compliant-device requirements (including Windows 365 for Agents), and applying Agent Risk-based conditions. As agentic AI identities proliferate in client tenants, this gives MSPs a familiar policy framework to extend Zero Trust controls to non-human, agent-driven accounts rather than treating them as an unmanaged blind spot.

Defender

Codename MDASH Brings Multi-Agent Vulnerability Scanning to Private Preview

Codename MDASH orchestrates a panel of specialized AI agents to discover, validate, and help remediate vulnerabilities across complex environments, routing confirmed findings into Defender workflows and engineering pipelines. MSPs supporting clients with custom or proprietary applications should consider signing up for the private preview, particularly where traditional scanners have historically missed logic-level vulnerabilities.

Defender Expands Local AI Agent Discovery to 25+ Agent Types, Adds macOS Coverage (Preview)

Defender now discovers more than 25 types of local AI agents and MCP servers across managed Windows and macOS devices, and can block prompt-injection attempts against coding agents like GitHub Copilot CLI or Claude Code at runtime. This builds meaningfully on last month’s Windows-only preview. MSPs should reassess client environments for macOS-based developer or power-user endpoints that were previously blind spots for local AI agent risk.

Defender for Cloud Extends Database Threat Protection to AWS RDS Open-Source Databases (GA)

Built-in threat detection for anomalous access and brute-force attempts, plus automated sensitive-data discovery, now covers open-source relational databases on Amazon RDS. For MSPs with clients running multi-cloud or AWS-hosted workloads, this closes a coverage gap without requiring a separate AWS-native tool.

Defender for Cloud Multicloud Coverage Expands Across AWS and Google Cloud

Microsoft added roughly 90 new resource types and 200+ security recommendations to multicloud coverage in Defender for Cloud. MSPs managing security posture across AWS and GCP alongside Azure should refresh client posture assessments, since previously invisible resource types may now be generating new findings.

Licensing

Microsoft 365 Business with Copilot SKUs Are Now Generally Available

As of July 1, the previously promotional Business Standard with Copilot ($23.50/user/month) and Business Premium with Copilot ($32/user/month) are now permanent, standalone SKUs (300-license cap, annual billing). Two companion promos also went live: Business Basic + Copilot Business at $21/user/month (25% off through December 2026), and standalone Copilot Business at $18/user/month (15% off through December 2026). MSPs should update quoting tools now โ€” every SMB renewal is a built-in, no-longer-time-boxed Copilot upsell.

New Licensing Prerequisite for Agent 365 Purchases

Effective June 1 and now formally documented for partners, new Agent 365 purchases require one of: Microsoft 365 E5/A5/Business Premium, or Defender Suite + Purview Suite (or their Edu/FLW equivalents). Microsoft 365 E7 customers are unaffected since E7 already bundles these. MSPs positioning Agent 365 should audit client licensing before the conversation goes further โ€” customers without the prerequisite may hit capability gaps mid-deployment.

FY27 CSP Promotions for Microsoft 365 and Copilot Extended and Expanded

ME3 and ME5 promotions (10โ€“20% off) are extended through September 30, 2026; ME7 promotions (10โ€“15% off) run through December 31, 2026. New SMB-only Copilot promotions launched July 1: 15% off 1-year (300โ€“999 licenses) and 30% off 1-year (1,000+ licenses), both through September 30. MSPs should prioritize accounts with existing E3/E5/Business investment and active Copilot pilots for expansion before these windows close.

New Windows 365 CSP Promotions Offer Up to 25% Off

Windows 365 Business gets 25% off through June 2027; Enterprise gets 20% off through September 30, 2026; Flex and Government get 20% off through June 2027. For MSPs selling Cloud PC alongside M365 management, this is a low-friction way to open cost-conscious client conversations.

Partner Code of Conduct Update Adds Anti-Corruption Remediation Requirements (Effective August 1)

Microsoft is adding a clause requiring partners to participate in anti-corruption and remediation programs when assigned, separate from standard compliance training. No immediate action is required, but MSPs should review the updated terms before the August 1 effective date.

Purview

DLP Can Now Inspect Text and AI Prompts at the Network Layer via Entra Global Secure Access (Preview)

A new DLP integration with Entra Global Secure Access intercepts and inspects text and AI interactions at the network layer โ€” across browsers, apps, APIs, and add-ins โ€” and can enforce DLP actions or feed Insider Risk Management based on risky activity. This is a notable escalation from app-level DLP: MSPs can now help clients prevent sensitive data from reaching untrusted generative AI platforms and social/collaboration tools regardless of which app or endpoint is being used.

Insider Risk Management Gets a Unified Alert Experience (Preview)

Classic and agent-triaged alerts now appear in a single alerts list, with agent summaries, alert details, and user details previewable inline. MSPs running insider risk programs for clients should expect a smoother triage workflow rather than switching between two dashboards.

Insider Risk Management Adds Expanded User Profile Signals (Preview)

The unified alert view now surfaces additional Entra-sourced user signals โ€” office location, employee type, department, and last working date โ€” directly alongside alerts. This gives MSP analysts faster context (e.g., is this a departing employee?) without pivoting to a separate HR or directory lookup.

Insider Risk Management Adds Notes on Alerts and Cases (Preview)

Analysts can now add and view notes on both alerts and cases, with system-generated notes automatically logged on status changes, reassignment, closure, or escalation. This creates a cleaner audit trail for MSPs that need to document investigative reasoning for client reporting or compliance purposes.

Teams

Teams Now Flags Automated Participants in Meetings

Teams can now help identify automated participants โ€” bots, AI note-takers, and similar automated join tools โ€” in meetings, giving organizers and admins more visibility into who or what is actually present. As AI meeting assistants proliferate across client organizations, MSPs should treat this as a useful visibility layer for clients concerned about unauthorized recording or data-capture tools joining sensitive meetings; it surfaces what’s present rather than blocking it outright.

Users Can Now Report and Block Suspicious Calls Directly in Teams

Teams now lets users flag a suspicious call and optionally block the caller directly from the call interface, feeding into Microsoft’s broader fraud and impersonation protections. MSPs supporting clients on Teams Phone should make sure end users know this option exists โ€” it’s a low-effort way to crowdsource fraud signal with no admin configuration required.

Image Sharing Now Preserves OneDrive/SharePoint Permissions

Quick share for images now preserves file-level permissions when the image lives in OneDrive or SharePoint, so recipients only get access if they’re already entitled to it โ€” though images pasted directly into chat don’t carry that same permission enforcement. MSPs advising clients on data-sharing hygiene should flag the paste-vs-share distinction, since it’s an easy way for permissions to quietly not apply the way an end user assumes.

Copilot

Copilot Chat in Outlook Expands to Reason Over Full Inbox, Calendar, and Enterprise Data โ€” No Copilot License Required

Copilot Chat in Outlook is expanding from single-thread reasoning to reasoning across a user’s entire inbox, calendar, meetings, and other Microsoft 365 data they already have access to โ€” and this applies even without a Microsoft 365 Copilot license. This is a meaningful expansion of what an “unlicensed” AI feature can see and use. MSPs should review Copilot Chat governance and data access policies now, since the scope of what this free-tier feature can surface just grew substantially.

Copilot-Generated Files Automatically Inherit Sensitivity Labels

When Microsoft 365 Copilot generates a file, it now automatically applies the highest sensitivity label found in the source data used to create it โ€” and notifies the user if it can’t determine an appropriate label. This closes a real data-governance gap where AI-generated output previously had no automatic protection inheritance. MSPs should confirm sensitivity label policies are actually configured for clients using Copilot generation features, since this control only helps if labels exist to inherit.

Admins Can Now Edit Permission Handling on Existing ServiceNow Copilot Connectors

Admins previously had to recreate ServiceNow Knowledge and Catalog connector configurations to adopt hierarchical permissions; they can now edit existing connections directly to switch between Simple and Advanced permission handling. MSPs managing ServiceNow-integrated Copilot deployments can now tighten permission models without a disruptive rebuild.

Watermarking Policy Now Available for AI-Generated Video and Audio

A new Cloud Policy service setting lets admins turn on visual or audio watermarks for AI-generated or AI-altered video and audio content in Microsoft 365 (image watermarking remains a separate, user-controlled setting). MSPs advising clients in regulated or reputation-sensitive industries should evaluate turning this on as a low-cost transparency control.

Outlook

No updates worth noting this month.

OneDrive & SharePoint

SharePoint Server Subscription Edition Security Update Ships With 26H1 Feature Update (KB5002873)

The June 9, 2026 cumulative update for SharePoint Server Subscription Edition (build 16.0.19725.20384) patches a large batch of CVEs, including remote code execution and spoofing vulnerabilities, and introduces the SharePoint Server Subscription Edition 26H1 feature update as a baseline for all future public updates. MSPs managing on-premises SharePoint farms should schedule patching now โ€” this replaces the prior KB5002863 update and closes several actively-tracked CVEs. No OneDrive-specific updates were published this period.


July’s list is shorter than June’s, but the shape of the changes matters more than the count: licensing is catching up to the AI push Microsoft has been driving all year, Entra and Purview are both extending governance to AI agents and AI data flows rather than just user identities and user data, and several previews from last month (Entra Backup and Recovery, local AI agent discovery) have already matured toward GA. For MSPs, the through-line is the same one from last month โ€” the AI surface area in Microsoft 365 keeps growing, and the compliance and access-control tooling around it is being built in near-real-time alongside it.

Cover Photo by Christian Wiediger on Unsplash

person using computer

Every new client onboard starts the same way: a senior technician logs into Partner Center, then Entra, then Defender, then Intune, rebuilding the same policies they built last week for a different client. Four hours later, the tenant is configured, but the security projects that were supposed to get done this quarter got bumped again.

MSPs automate Microsoft 365 onboarding by replacing that portal-hopping with templated workflows that push a security baseline to a new tenant in minutes instead of hours. This article covers the full process, from tenant connection through drift monitoring, and shows where automation delivers leverage and where human judgment still matters.

What M365 onboarding includes for an MSP

MSPs automate Microsoft 365 onboarding by connecting identity workflows, security baseline templates, and multi-tenant management platforms into a single repeatable process. When a new client signs, the MSP connects to the tenant through Partner Center, runs an audit against a predefined baseline, and pushes Conditional Access, Defender, and Intune policies in one deployment. The work that used to require logging into four or five admin portals now happens from one dashboard.

M365 onboarding in the MSP context actually covers two distinct workflows that often get lumped together. Client onboarding is the initial setup of a new tenant relationship, including GDAP configuration, baseline deployment, and documentation. User provisioning is the ongoing work of adding and removing individual users after the client is already live.

A complete client onboarding typically includes:

  • Tenant connection: Partner Center setup, GDAP roles, and admin consent
  • Environment audit: Comparing current state to the MSP’s security standard
  • Security baseline deployment: Conditional Access policies, Defender settings, Intune enrollment configuration
  • User provisioning setup: License assignment rules, group templates, mailbox and Teams defaults
  • Documentation and handoff: Recording what was deployed and who owns ongoing management

Why manual M365 onboarding breaks at scale

The operational ceiling hits faster than most MSPs expect. When every onboard requires a senior technician to log into Entra, then Defender, then Intune, then Partner Center, the math stops working somewhere around 30 to 40 clients. At that point, growth becomes a headcount problem instead of a process problem.

Senior technician hours spent on L1 work

Portal-hopping across Microsoft admin centers eats senior time on work that could be templated. A single client onboard can take four to six hours of senior technician time when done manually. That time comes directly out of project work, escalations, and the security improvements that keep getting bumped because break-fix jumped the queue again.

Inconsistent baselines across client tenants

Without a standard, each technician builds configurations differently. One tech enables MFA with a 14-day grace period, another sets it to immediate enforcement, and a third forgets to exclude the break-glass account. Six months later, the MSP has 40 tenants with 40 slightly different security postures, and no easy way to know which is which.

Security gaps that surface after go-live

Skipped steps during manual onboarding create vulnerabilities that only appear later. A missed Conditional Access policy or an incomplete Defender configuration becomes a client call three months down the road. Without an audit trail, there is no way to know what was actually deployed versus what was supposed to be deployed.

Onboarding capacity capped by headcount

Manual onboarding ties growth directly to hiring. If each onboard takes a senior tech six hours, and the senior tech has 30 available hours per week for project work, the MSP can onboard roughly five clients per week at maximum capacity. Automation changes that ratio entirely.

What can be automated in M365 onboarding and what still needs a human

Not everything in onboarding is automatable, and setting realistic expectations upfront prevents frustration later. The technical deployment work automates well. The scoping conversations and exception handling still require human judgment.

Can be automated Still needs a human
Security baseline deployment Scoping and success criteria
License and group assignment Exception handling for custom client needs
Policy push to Entra, Defender, Intune Client communication and kickoff
Environment audit against baseline Validating exceptions and sign-off
Drift detection post-onboarding Escalation and remediation decisions

The goal is not to remove humans from the process. The goal is to remove humans from the repetitive parts so they can focus on the parts that actually require judgment.

How to automate M365 client onboarding step by step

The workflow below covers the full onboarding process from signed contract to go-live. Each step identifies what gets automated and what the technician still handles manually.

Step 1. Confirm scope, licensing, and success criteria

Automation starts with clean inputs. The technician confirms which M365 licenses the client has, what is in scope for the engagement, and what success looks like. Business Premium or equivalent licensing is typically required for the security features that deliver ROI. This step is human work, and skipping it creates problems downstream.

Step 2. Connect the tenant through Partner Center

GDAP setup and tenant connection happen through Partner Center. GDAP, or Granular Delegated Admin Privileges, is Microsoft’s model for giving MSPs access to client tenants with specific role assignments rather than full admin rights.

Some platforms automate the invitation workflow and role assignment, reducing the manual steps from a dozen clicks to a single action. The technician still verifies the connection completed correctly before moving on.

Step 3. Audit the existing environment against a baseline

The platform scans the tenant and compares it to the MSP’s security baseline. The output is a gap report showing what policies exist, what is missing, and what conflicts with the standard. This audit takes minutes instead of the hour or more required to check each setting manually across multiple admin portals.

Step 4. Deploy the security baseline across Entra, Defender, and Intune

This is where automation delivers the most leverage. Platforms like Augmentt let the MSP build a baseline once and deploy it to a new client in minutes. Junior technicians can run the deployment through a prompted workflow without senior oversight on every step, because the platform guides them through the process and prevents configuration errors.

Step 5. Validate the deployment and document exceptions

After deployment, the technician confirms policies applied correctly and documents any client-specific exceptions. Some clients have legacy applications that require Conditional Access exclusions, or specific compliance requirements that modify the standard baseline. Those exceptions get logged for audit and future reference.

Step 6. Hand off to drift monitoring and reporting

The onboarded tenant moves into ongoing management. Drift detection watches for policy changes and flags them before they become client calls. Reporting captures what was deployed for QBRs and compliance documentation. The onboarding is complete, but the monitoring continues.

How to automate M365 user provisioning and offboarding

User provisioning and offboarding are separate workflows from client onboarding, though they often get bundled together in conversation. Once the client is live, adding and removing users becomes a repeatable process that benefits from templating.

Identity and license assignment

Entra ID user creation and license assignment can be automated based on role or group membership. When a new hire is logged in the client’s HR system or submitted through a form, the workflow creates the account and assigns the appropriate license without manual intervention. The technician does not touch the admin portal for routine user adds.

Group, policy, and Conditional Access placement

Users get placed into security groups automatically based on templates. A new sales hire goes into the sales group, which inherits the appropriate Conditional Access policies and application access. The logic is defined once and applied consistently, rather than configured individually for each user.

Mailbox, SharePoint, and Teams configuration

Collaboration tools provision alongside the user account. Mailbox setup, SharePoint permissions, and Teams membership follow the same template logic. The user has access to the right resources on day one without a technician manually configuring each service.

Endpoint enrollment through Intune

Device enrollment and compliance policy assignment can be automated for new users. When the user signs into their device, Intune enrollment triggers automatically and applies the appropriate compliance policies. The device is managed from the moment it connects.

Why multi-tenant architecture beats a golden tenant workaround

Some tools require a golden tenant or master account to push policies across client environments. A golden tenant is a reference environment where the MSP configures all their standard policies, then copies or syncs those policies to client tenants. This workaround creates maintenance overhead and breaks when Microsoft updates admin portals or changes how policies are structured.

True multi-tenant architecture works differently. The MSP manages every tenant independently with consistent configuration, but without a reference tenant to maintain. There are no scripts to update when Microsoft changes something, and no workaround to rebuild every few months.

  • Golden tenant approach: Requires a reference tenant, policies copied manually or via scripts, breaks when Microsoft updates admin portals
  • True multi-tenant architecture: Every tenant managed independently, baseline applied directly, platform handles Microsoft changes

Augmentt is built for true multi-tenant delivery. Every engineer on the team can work in any client environment with consistent configuration, and the platform keeps up with Microsoft when it changes something rather than requiring the MSP to rebuild their process.

Why Microsoft Lighthouse and Partner Center fall short for automated onboarding

Lighthouse and Partner Center provide visibility across tenants, but visibility is not automation. MSPs still log into each tenant to configure policies, and there is no baseline templating or deployment workflow built in.

The limitations become apparent quickly:

  • No baseline templating or deployment automation
  • No drift detection or auto-remediation
  • Limited alerting and no client-facing reporting
  • Manual work required in each tenant for policy configuration

For MSPs managing 500 or more seats across their client base, the native tools become a bottleneck rather than a solution. Lighthouse shows what exists, but it does not help deploy or maintain a consistent standard.

How to delegate M365 onboarding to L1 and L2 technicians

Automation enables delegation. When onboarding is templated and prompted, junior technicians can run the process without senior oversight on every step. The senior technician’s time goes to work that actually requires their expertise, like exception handling and escalations.

Effective delegation requires a few things to be in place:

  • Templated workflows: Junior techs follow prompted steps, not custom builds
  • Guardrails: Platform prevents configuration errors before they happen
  • Least-privilege access: Techs only see and touch what they need for the task
  • Audit trail: Every action logged for review by senior staff

Augmentt’s L1/L2 delegation capabilities let MSPs scale their onboarding capacity without scaling senior headcount. The junior tech runs the deployment, the platform prevents mistakes, and the senior tech reviews the output rather than doing the work themselves.

How to keep the M365 baseline consistent after go-live

Onboarding is not the end. The baseline drifts over time as users, admins, and Microsoft make changes. A client admin disables a Conditional Access policy to troubleshoot a login issue and forgets to re-enable it. Microsoft updates a default setting. A user gets added to the wrong group. Maintaining consistency requires ongoing monitoring.

Drift detection against the deployed baseline

The platform monitors for policy changes and flags drift before it becomes a client call. When a Conditional Access policy gets modified or disabled, the alert includes the details and the remediation action in the same view. The technician knows what changed and what to do about it without digging through logs.

Auto-remediation for common policy changes

Defined alert types can be handled automatically. The environment is protected before the team sees the alert. Overnight changes do not become morning triage, because the platform already reverted the unauthorized modification.

Client-facing reports that prove the work

QBR-ready reports show what was deployed, what drifted, and what was remediated. Augmentt generates branded, schedulable reports as a byproduct of the platform’s work. The report goes out with the bill, and the client sees exactly what the MSP caught and fixed.

See how Augmentt handles baseline deployment, drift detection, and client reporting from one dashboard โ†’

Frequently asked questions about automating M365 onboarding

How long does an automated M365 client onboarding take?

Automated baseline deployment can reduce the technical work from hours to minutes. Total time depends on scoping, exception handling, and validation, which still require human time. The deployment itself is fast; the conversations around it take longer.

Can an MSP automate M365 onboarding without using a golden tenant?

Yes. Platforms with true multi-tenant architecture deploy baselines directly to each client tenant without a golden tenant or master account workaround. The baseline is defined in the platform and applied to each tenant independently.

Does Microsoft Lighthouse automate M365 onboarding for MSPs?

Lighthouse provides visibility across tenants but does not automate baseline deployment, drift detection, or client-facing reporting. MSPs still need a separate platform for full onboarding automation.

Can L1 technicians safely run an automated M365 onboarding?

With templated workflows and guardrails, L1 techs can execute onboarding without senior oversight on every step. The platform prevents configuration errors and logs every action for review. The senior tech reviews the output rather than doing the work.

Cover Photo by Lush Kooch on Unsplash

MSPs standardize device security in Microsoft Intune, then spend their time keeping every client tenant in line as Microsoft changes settings, clients add devices, and compliance requirements shift. Augmentt already handled the core of that: configuration, compliance, and deployment profiles, built once and applied per tenant, edited inline without logging into each customer portal.

This release goes further. Here is what is new and what it means for your team.

Deploy apps and scripts across tenants

Most MSPs have a standard stack, a set of approved applications and scripts they deploy to every client environment. In a single-tenant world, that means logging into each portal, finding the right policy, and pushing the deployment manually. Multiply that by the number of clients you support and it becomes one of those tasks that consumes technician hours without adding any visible value to the client or the business.

With this release, the apps and scripts you have packaged can now be deployed across your client tenants directly from Augmentt. You set it up once and push it where it needs to go, without switching between portals. For MSPs managing more tenants than their team can realistically touch by hand, this is the kind of operation that should have always worked this way.

Manage iOS MDM policies across tenants

iOS device management is increasingly part of the conversation with clients, especially those with field teams, executives on iPhones, or any environment where mobile devices touch business data. The problem MSPs run into is the same one they face with every other Intune configuration: policies have to be set per tenant, which means the work scales with the number of clients you have rather than the quality of your process.

iOS MDM policies are now managed in Augmentt alongside your Windows configuration work. You set your policies up once, apply them per tenant, and edit them inline when something needs to change. Mobile device management no longer lives in a separate workflow from the rest of your Intune work, which sounds like a small thing until you are trying to push a policy change across thirty client environments before the end of the day.

Patch management through our Robopack partnership

Patch management is one of the clearest value propositions an MSP can sell. Clients want to know their devices are up to date, and you want to be able to prove it without it consuming your team. The challenge is that doing it well requires reliable packaging and deployment, which is where a lot of in-house patch workflows break down and where the manual cleanup starts.

Through our partnership with Robopack, patch management is now available in Augmentt. Robopack handles application packaging at a level that takes the fragility out of the process, and it is accessible from the same console where you manage the rest of your Intune environment. More of what you run in Intune, including keeping devices current, is handled without leaving the platform.

Device compliance visibility across every tenant

One of the persistent frustrations of managing Intune across multiple clients is that compliance alerts live in each tenant’s portal. If a device falls out of compliance, you find out when you happen to be in that portal, or when the client tells you. Neither is a great position to be in when your pitch to clients is that you are managing their security proactively.

Microsoft’s device-compliance alerts are now surfaced for all your client tenants in a single view inside Augmentt. You see the full compliance picture across your book of business without checking portals one by one, which makes it a lot easier to catch issues before clients do and to report on device health in a way that actually means something to the people paying for the service.

Taken together, more of what MSPs do in Intune on a daily basis is now handled from one console. If you want to see it in action, try it for free today!

SUBSCRIBE for more resources

Run Unlimited Free M365 Security Reports

Across All Your Customers. Forever.

What our partners are saying

MSPs Leading With Augmentt

Why They Chose Augmentt:

โ€œWe built an entire managed service around the Augmentt platform so we can sell our customers a service that will keep their tenants up to date and configured all the time rather than needing to do these professional services engagements periodically. I think not only has the quality improved, but itโ€™s opened up an entirely new service. Weโ€™ve been able to sell to our customers very successfully.โ€

โ€“ Tim Campbell, All Covered
What Theyโ€™re Using Augmentt For:

Ready to get started?

Protect your customers from the growing cyber security threat landscape while growing your MSP by selling enhanced SaaS security services.
Monthly Update Webinar
Get the latest platform updates live every month!
Watch Demo
Take a self guided tour of the Augmentt platform.

ยฉ 2026 Augmentt. All Rights Reserved.

Terms & ConditionsPrivacy Policy