What’s New in M365 for MSPs — August 2026

Table of Contents

August was quiet on licensing and identity, but it brought a SharePoint Server patch every on-prem admin needs to act on, a heavy round of Copilot changes with real governance implications, and a clear pattern across Defender: Microsoft is building security controls around AI agents before they become the next unmanaged risk category. Here’s what matters if you’re managing Microsoft 365 across multiple tenants.

Intune

Samsung Knox E-FOTA firmware management for Android Enterprise (week of July 27)

Intune now integrates with Samsung Knox E-FOTA to manage firmware updates for corporate-owned Samsung devices from the admin center, letting you control which firmware versions deploy, schedule updates around a client’s business hours, and push them without user interaction, useful once you’re managing firmware across a large Android fleet spread over several tenants.

New Windows settings catalog entries (week of July 27)

Camera behavior, Keyboard Filter, WSL, OneDrive folder naming, and Edge 148/149 policies are now manageable through the settings catalog, and since none require a new profile type, you can fold them into existing baselines instead of building tenant-by-tenant configuration profiles, the kind of standardization Intune Autopilot is built to apply across every client at once.

Regional Microsoft Store app support (week of July 27)

Admins can now target region-specific Microsoft Store catalogs when deploying apps, closing a gap for multi-regional clients who previously couldn’t get apps outside the US catalog without sideloading.

Custom compliance settings for macOS (week of July 27)

Script- and JSON-based custom compliance checks, already available for Windows and Linux, now work on macOS too, so you can run one compliance framework across every platform in a tenant instead of a Windows-only setup plus manual Mac checks.

Controlled Configuration for Microsoft Defender antivirus, preview (week of July 27)

Defender antivirus settings managed through Intune can now override Group Policy, Configuration Manager, and local scripts, which in hybrid-managed environments stops a leftover GPO from silently overriding a setting you thought was locked in.

Entra ID

No updates worth noting this month.

Defender

Vulnerability assessment for Microsoft Store applications, preview (August)

Defender for Endpoint now surfaces vulnerabilities in Microsoft Store apps, including Teams, Firefox, WhatsApp, Slack, and Dropbox, with file paths and version detail, giving you visibility into consumer-grade apps that land on corporate devices whether or not you sanctioned them.

Defender for Endpoint macOS build 101.26062.0011, GA (August)

A new generally available macOS build shipped with a set of fixes and enhancements. Routine, schedule it into your normal Mac patch cadence.

AI agent posture risk in Microsoft Defender, preview (July)

Defender now scores posture risk for enterprise and locally discovered AI agents based on configuration, access, runtime activity, and active alerts, giving you a place to catch a client running an unsanctioned AI agent and prioritize it for remediation instead of it getting buried in a general alert feed.

Domain investigation page, GA (July)

A centralized view of Active Directory domain security, deployment health, service accounts, sensitive entities, group policies, and trust relationships, useful for pulling together AD domain posture across a client’s infrastructure in one screen instead of piecing it together manually.

Threat detection and real-time protection for Microsoft Agent 365 agents (July)

Defender now analyzes runtime signals from AI agent tool usage and can allow or block interactions with MCP tooling servers in real time. Agentic AI is quickly becoming a standard part of the threat surface you’re expected to monitor, worth getting ahead of before a client asks if you’re covering it, and the kind of baseline monitoring Secure Autopilot helps you keep consistent across every tenant.

Licensing

No updates worth noting this month.

Purview

Auto-labeling policy simulation mode (August)

You can now run an auto-labeling policy in simulation mode to preview what it would label before enforcing it, reviewing match results and source distribution first, a safe way to validate a policy against a client’s real content instead of discovering it over- or under-labels after enforcement is already live.

Auto-labeling policy Insights tab (August)

A new tab on the policy details page reports performance metrics for auto-labeling policies in both simulation and enforcement mode, giving you quick, concrete evidence to show a client that a labeling policy is doing what you told them it would.

Teams

Nothing landed in the Desktop & Web changelog this August. The most recent additions from July, a Meeting Recaps app and a fix that makes Teams for web remember sign-in preferences across sessions, don’t require any action.

Copilot

August was a heavy month for Copilot. A few items below are worth a governance review, not just a features read.

ServiceNow connectors support role-based permissions (August 11)

ServiceNow Knowledge and Catalog connectors now enforce access based on user roles like admin or knowledge manager, instead of user criteria alone, worth an audit of any client’s ServiceNow connector configuration to confirm permissions are mapped correctly rather than assuming the old setup still behaves the same way.

SharePoint Authoritative Sites (August 11)

Admins can designate specific SharePoint sites as authoritative so Copilot prioritizes trusted content, like company policy and official news, in search results, a concrete lever for improving Copilot answer quality in a client tenant and worth adding to your Copilot rollout checklist.

Copilot in PowerPoint can reference web sources (August 11)

When generating a presentation, Copilot can now pull in and cite current web sources, which means content from outside the tenant boundary can end up in a client deliverable. Worth checking against any client’s DLP or content filtering policy before it reaches end users.

Consumption Dashboard tracks Copilot credit usage (August 11)

Viva Insights now shows Copilot credit consumption for Cowork and Work IQ API services, visible to managers with five or more reports, Insights analysts, and Global admins, the first real per-tenant visibility into Copilot usage costs and useful the next time a client asks why their AI bill went up.

Outlook

Go to Folder dialog and a fourth message list column (August 14)

New Outlook for Windows added a Go to Folder dialog (Ctrl+Y or mailbox context menu) and an extra content column in the message list when sorting is applied. Minor, but worth mentioning to power users who ask about navigation.

Inbox rules support “mentions you” and external sender conditions (August 7)

New rule conditions for messages that mention you directly or come from outside the organization give clients a genuinely useful control for cutting down on missed messages, and double as light phishing awareness.

Bulk contact deletion, up to 100 at a time (August 7)

Contacts can now be deleted in bulk instead of one at a time, a small but real time saver for your technicians cleaning up after offboarding rounds.

OneDrive & SharePoint

SharePoint Server Subscription Edition security update, KB5002893 (August 11)

Patches SharePoint Server Subscription Edition (build 16.0.19725.20522) against 26 CVEs, including remote code execution, information disclosure, spoofing, security feature bypass, and elevation of privilege. Also disables file-backed Business Data Connectivity model imports by default. Environments running SharePoint Workflow Manager need KB5002799 installed first. This is the must-do item this month: any client still running on-premises SharePoint Server needs this patched now, not on the next routine cycle.

OneDrive sync client for Windows, build 26.119.0622.0003 (July 10)

Fixed a bug where the sync client checked Folder Shortcuts against the wrong root path when validating max path length, which should reduce false “path too long” errors and the support tickets that come with them. Nothing else notable has shipped since.

The bottom line

August didn’t bring the licensing or identity shake-ups we’ve seen in past months, but the pattern worth watching is Defender and Copilot building governance and security tooling around AI agents ahead of them becoming widespread in customer tenants. Add a mandatory SharePoint Server patch and two quiet Purview improvements for safely testing labeling policies, and there’s enough here to work into next month’s client reviews even without a headline feature launch.

If you’d rather not track all of this manually every month, you can start a free trial of Augmentt and see how much of it runs on autopilot instead.

FAQ

What is the most urgent Microsoft 365 update for MSPs this August?

The SharePoint Server Subscription Edition security update (KB5002893), released August 11, patches 26 CVEs including remote code execution and elevation of privilege vulnerabilities. Any MSP with clients running on-premises SharePoint Server should schedule this immediately rather than waiting for a routine patch cycle.

Did Microsoft Entra ID or licensing change this month?

No. August was quiet on both fronts, with no notable Entra ID or CSP licensing changes to report.

What’s new with Microsoft Defender for AI agents?

Defender added posture risk assessment for enterprise and local AI agents, runtime threat detection for Microsoft Agent 365 agents, and real-time protection that can allow or block interactions with MCP tooling servers. Together these give security teams visibility into AI agents that might otherwise go unmanaged inside a tenant.

Should MSPs be concerned about Copilot in PowerPoint referencing web sources?

It’s worth reviewing rather than being alarmed by. The feature lets Copilot pull in outside content when building a presentation, which can conflict with a client’s DLP or content filtering policies if those aren’t already accounting for it. Confirm those policies before the feature reaches end users.

What changed with Purview auto-labeling this month?

Purview added simulation mode for auto-labeling policies, letting admins preview what a policy would label before enforcing it, plus a new Insights tab reporting on policy performance. Both make it easier to validate a labeling policy against real tenant content before turning it on.

Is there anything MSPs need to do about the new Copilot Consumption Dashboard?

Not urgently. The dashboard, in Viva Insights, gives managers and admins visibility into Copilot credit usage for Cowork and Work IQ API services, useful the next time a client asks why their AI costs went up.

Did Teams get any updates MSPs need to act on this month?

No significant changes landed in the Teams Desktop & Web changelog in August. The Meeting Recaps app and improved web sign-in persistence, both from July, are worth knowing about but don’t change how you manage tenants.

Where can MSPs find these updates directly from Microsoft?

Microsoft publishes ongoing changelogs for each product: the Intune what’s new page, the Defender for Endpoint and Defender XDR what’s new pages, the Purview what’s new page, Microsoft 365 Copilot release notes, the New Outlook and Outlook Mobile release notes, and the SharePoint/OneDrive sync release notes. Checking these directly is useful between monthly roundups if something urgent ships mid-month.

Photo credit: Zulfugar Karimov on Unsplash

Author
Gavin Garbutt
Co-Founder & Chairman of Augmentt

FAQ

Using our GDAP tool & Magic Link, setting up is easy! You can integrate with your CSP partner portal in minutes
Augmentt uses a combination of Microsoft Secure Score best practices as well as industry standards such as NIST & CIS. You can use the out of box templates to get started right away and even build your own custom templates to match your client requirements.
Out of box, Augmentt comes pre-configured to not be noisy. Very few Microsoft alerts are critical in nature so you will be receiving tickets for account breaches and not minor user log related events. That said, everything is customizable and you can turn alerts on & off to match your clients’ needs.
No. You can choose to schedule alerts to any stakeholder you want and at the frequency you want or manually download reports when you need them.
Regardless of how MFA is managed across your tenants, we have you covered. Augmentt supports Conditional Access Policies, Security Defaults, Entra ID per user (Legacy) MFA as well as 3rd party MFA services like DUO.
No. You can use Augmentt to monitor and manage all clients regardless of their licensing. For environments with no premium licensing you can still provide alerts and monitoring for account breaches and configure security best practices. For environments with premium licensing, you can leverage Microsoft’s premium alerts and premium security configurations such as Conditional Access Policies.
Augmentt is one of the few vendors SOC 2 Type II, and GDPR compliant.
Site licenses to make sure you can deliver standardized service across all clients very affordably.

SUBSCRIBE for more resources

Related Content

Policy Sprawl Is Killing MSP Efficiency
Policy sprawl is quietly draining your margins, creating security gaps, and eroding client trust. The good news? Standardization is the cure.
Does Microsoft Secure Score Tell the Whole Story?
Do you have a complete understanding of your security? See why MSPs need to understand the role licensing plays in Secure Score results.
Top 10 M365 Security Best Practices for MSPs
Here are the top M365 security best practices to help you enhance protection, ensure compliance, and stay ahead of emerging threats.