What’s New in M365 for MSPs — July 2026

Table of Contents

July 2026 brings a lighter but no less consequential wave of Microsoft 365 changes: licensing finally catches up with the Copilot promotional push, Entra ships several identity-governance upgrades, and Purview starts locking down AI data flows at the network layer. A few items carry hard dates worth calendaring now.

Intune

Advanced Intune Capabilities Are Rolling Into Microsoft 365 E3 and E5

Microsoft is folding several Intune Suite capabilities directly into Microsoft 365 E3 and E5, no separate add-on required. E3 (via EMS E3) gains Remote Help, Advanced Analytics, and Intune Plan 2 (Microsoft Tunnel for MAM, specialty device management, FOTA updates). E5 adds Endpoint Privilege Management, Enterprise Application Management, and Microsoft Cloud PKI on top of that. Rollout is automatic and gradual, with a 30-day admin center notice before it lands in any given tenant. MSPs should revisit client licensing conversations now — capabilities you may have been quoting as a paid upsell are about to become “already included” for E3/E5 clients, which changes both your pricing story and your renewal risk.

Multi Admin Approval Now Enforces on API Calls Made by Automation

Multi Admin Approval (MAA) previously only gated interactive admin actions; it now also applies to Microsoft Graph API calls made by service principals, scripts, and third-party tools. If a tenant has MAA policies configured, automation lacking the required approval headers will start returning HTTP 403 errors. MSPs running RMM or custom Graph-based automation against MAA-enabled tenants need to update those scripts to the new approval workflow, or use the new Exclusions tab to carve out specific applications before this breaks a client’s automated workflows.

New Android Enterprise Setting Blocks Apps From Exposing Functions to AI Agents

A new settings catalog option, “Block apps from exposing app functions,” lets admins prevent managed apps on corporate-owned Android devices from exposing programmatic actions that on-device AI agents or assistants can invoke. As agentic AI features spread across mobile OSes, MSPs should treat this as a new baseline control worth adding to Android Enterprise configuration profiles, particularly for clients with regulated or sensitive data on managed devices.

Managed Win32 App Content Now Requires HTTPS Delivery

Intune now requires HTTPS for managed Win32 app content delivery. This mainly affects organizations using Microsoft Connected Cache without HTTPS configured on their cache nodes — those clients will silently fall back to CDN delivery, bypassing the cache and increasing internet bandwidth usage. MSPs managing Connected Cache deployments should audit cache node configuration now rather than waiting for a client to notice slower or costlier app deployments.

ChatGPT Added as a Protected App for Intune

ChatGPT is now available as a protected app under Intune’s app protection policy framework, meaning MAM controls (data cut/copy/paste restrictions, save-as blocks, etc.) can be applied to it like other managed apps. With generative AI tools spreading into client environments largely ungoverned, MSPs should treat this as an opportunity to bring at least one major GenAI consumer app under formal data-loss controls.

Entra ID

Microsoft Entra Backup and Recovery Reaches General Availability

Entra Backup and Recovery — daily, Microsoft-managed snapshots of core directory objects (users, groups, apps, service principals, Conditional Access policies, and more) — is now generally available, having been in preview as recently as last month. Tenants with Entra ID P1/P2 get one backup per day retained for 7 days, with diff reports and point-in-time restore. MSPs should formally add this to incident response runbooks now that it’s GA rather than treating it as an optional preview feature.

New Built-In “SOC Identity Responder” Role for Defender-Initiated Containment (Preview)

A new built-in Entra role lets SOC analysts perform identity containment actions — disabling users, revoking sessions, forcing password resets — triggered from Microsoft Defender, without being granted broad directory admin privileges. It supports role-assignable groups and optional PIM just-in-time activation. For MSPs running a SOC or MDR-style service across client tenants, this closes a real gap where analysts previously needed high-privilege roles just to act on an active incident.

AD Group Enforcement Prevents Drift Between Entra and On-Prem AD Groups (Preview)

For hybrid environments using group provisioning to Active Directory, admins can now designate specific AD groups so that changes are only accepted if made through the Entra provisioning service — direct edits made outside Entra are blocked. This is a meaningful control for MSPs managing hybrid identity, where AD group drift is a common source of access-review headaches and audit findings.

BYOD Support for Windows Client Using Entra Registration Reaches GA

Windows BYOD support via Entra-registered (not domain-joined) devices is now generally available, letting users and partners access corporate resources from personal Windows devices via the Private Application traffic profile, including internal guest users. MSPs supporting clients with contractor or BYOD-heavy workforces can now offer a fully supported non-domain-joined access path instead of workarounds.

Conditional Access Gains Dedicated Controls for AI Agent Accounts (Preview)

Conditional Access now supports targeting AI agents’ user accounts directly — scoping policies by custom security attributes, enforcing compliant-device requirements (including Windows 365 for Agents), and applying Agent Risk-based conditions. As agentic AI identities proliferate in client tenants, this gives MSPs a familiar policy framework to extend Zero Trust controls to non-human, agent-driven accounts rather than treating them as an unmanaged blind spot.

Defender

Codename MDASH Brings Multi-Agent Vulnerability Scanning to Private Preview

Codename MDASH orchestrates a panel of specialized AI agents to discover, validate, and help remediate vulnerabilities across complex environments, routing confirmed findings into Defender workflows and engineering pipelines. MSPs supporting clients with custom or proprietary applications should consider signing up for the private preview, particularly where traditional scanners have historically missed logic-level vulnerabilities.

Defender Expands Local AI Agent Discovery to 25+ Agent Types, Adds macOS Coverage (Preview)

Defender now discovers more than 25 types of local AI agents and MCP servers across managed Windows and macOS devices, and can block prompt-injection attempts against coding agents like GitHub Copilot CLI or Claude Code at runtime. This builds meaningfully on last month’s Windows-only preview. MSPs should reassess client environments for macOS-based developer or power-user endpoints that were previously blind spots for local AI agent risk.

Defender for Cloud Extends Database Threat Protection to AWS RDS Open-Source Databases (GA)

Built-in threat detection for anomalous access and brute-force attempts, plus automated sensitive-data discovery, now covers open-source relational databases on Amazon RDS. For MSPs with clients running multi-cloud or AWS-hosted workloads, this closes a coverage gap without requiring a separate AWS-native tool.

Defender for Cloud Multicloud Coverage Expands Across AWS and Google Cloud

Microsoft added roughly 90 new resource types and 200+ security recommendations to multicloud coverage in Defender for Cloud. MSPs managing security posture across AWS and GCP alongside Azure should refresh client posture assessments, since previously invisible resource types may now be generating new findings.

Licensing

Microsoft 365 Business with Copilot SKUs Are Now Generally Available

As of July 1, the previously promotional Business Standard with Copilot ($23.50/user/month) and Business Premium with Copilot ($32/user/month) are now permanent, standalone SKUs (300-license cap, annual billing). Two companion promos also went live: Business Basic + Copilot Business at $21/user/month (25% off through December 2026), and standalone Copilot Business at $18/user/month (15% off through December 2026). MSPs should update quoting tools now — every SMB renewal is a built-in, no-longer-time-boxed Copilot upsell.

New Licensing Prerequisite for Agent 365 Purchases

Effective June 1 and now formally documented for partners, new Agent 365 purchases require one of: Microsoft 365 E5/A5/Business Premium, or Defender Suite + Purview Suite (or their Edu/FLW equivalents). Microsoft 365 E7 customers are unaffected since E7 already bundles these. MSPs positioning Agent 365 should audit client licensing before the conversation goes further — customers without the prerequisite may hit capability gaps mid-deployment.

FY27 CSP Promotions for Microsoft 365 and Copilot Extended and Expanded

ME3 and ME5 promotions (10–20% off) are extended through September 30, 2026; ME7 promotions (10–15% off) run through December 31, 2026. New SMB-only Copilot promotions launched July 1: 15% off 1-year (300–999 licenses) and 30% off 1-year (1,000+ licenses), both through September 30. MSPs should prioritize accounts with existing E3/E5/Business investment and active Copilot pilots for expansion before these windows close.

New Windows 365 CSP Promotions Offer Up to 25% Off

Windows 365 Business gets 25% off through June 2027; Enterprise gets 20% off through September 30, 2026; Flex and Government get 20% off through June 2027. For MSPs selling Cloud PC alongside M365 management, this is a low-friction way to open cost-conscious client conversations.

Partner Code of Conduct Update Adds Anti-Corruption Remediation Requirements (Effective August 1)

Microsoft is adding a clause requiring partners to participate in anti-corruption and remediation programs when assigned, separate from standard compliance training. No immediate action is required, but MSPs should review the updated terms before the August 1 effective date.

Purview

DLP Can Now Inspect Text and AI Prompts at the Network Layer via Entra Global Secure Access (Preview)

A new DLP integration with Entra Global Secure Access intercepts and inspects text and AI interactions at the network layer — across browsers, apps, APIs, and add-ins — and can enforce DLP actions or feed Insider Risk Management based on risky activity. This is a notable escalation from app-level DLP: MSPs can now help clients prevent sensitive data from reaching untrusted generative AI platforms and social/collaboration tools regardless of which app or endpoint is being used.

Insider Risk Management Gets a Unified Alert Experience (Preview)

Classic and agent-triaged alerts now appear in a single alerts list, with agent summaries, alert details, and user details previewable inline. MSPs running insider risk programs for clients should expect a smoother triage workflow rather than switching between two dashboards.

Insider Risk Management Adds Expanded User Profile Signals (Preview)

The unified alert view now surfaces additional Entra-sourced user signals — office location, employee type, department, and last working date — directly alongside alerts. This gives MSP analysts faster context (e.g., is this a departing employee?) without pivoting to a separate HR or directory lookup.

Insider Risk Management Adds Notes on Alerts and Cases (Preview)

Analysts can now add and view notes on both alerts and cases, with system-generated notes automatically logged on status changes, reassignment, closure, or escalation. This creates a cleaner audit trail for MSPs that need to document investigative reasoning for client reporting or compliance purposes.

Teams

Teams Now Flags Automated Participants in Meetings

Teams can now help identify automated participants — bots, AI note-takers, and similar automated join tools — in meetings, giving organizers and admins more visibility into who or what is actually present. As AI meeting assistants proliferate across client organizations, MSPs should treat this as a useful visibility layer for clients concerned about unauthorized recording or data-capture tools joining sensitive meetings; it surfaces what’s present rather than blocking it outright.

Users Can Now Report and Block Suspicious Calls Directly in Teams

Teams now lets users flag a suspicious call and optionally block the caller directly from the call interface, feeding into Microsoft’s broader fraud and impersonation protections. MSPs supporting clients on Teams Phone should make sure end users know this option exists — it’s a low-effort way to crowdsource fraud signal with no admin configuration required.

Image Sharing Now Preserves OneDrive/SharePoint Permissions

Quick share for images now preserves file-level permissions when the image lives in OneDrive or SharePoint, so recipients only get access if they’re already entitled to it — though images pasted directly into chat don’t carry that same permission enforcement. MSPs advising clients on data-sharing hygiene should flag the paste-vs-share distinction, since it’s an easy way for permissions to quietly not apply the way an end user assumes.

Copilot

Copilot Chat in Outlook Expands to Reason Over Full Inbox, Calendar, and Enterprise Data — No Copilot License Required

Copilot Chat in Outlook is expanding from single-thread reasoning to reasoning across a user’s entire inbox, calendar, meetings, and other Microsoft 365 data they already have access to — and this applies even without a Microsoft 365 Copilot license. This is a meaningful expansion of what an “unlicensed” AI feature can see and use. MSPs should review Copilot Chat governance and data access policies now, since the scope of what this free-tier feature can surface just grew substantially.

Copilot-Generated Files Automatically Inherit Sensitivity Labels

When Microsoft 365 Copilot generates a file, it now automatically applies the highest sensitivity label found in the source data used to create it — and notifies the user if it can’t determine an appropriate label. This closes a real data-governance gap where AI-generated output previously had no automatic protection inheritance. MSPs should confirm sensitivity label policies are actually configured for clients using Copilot generation features, since this control only helps if labels exist to inherit.

Admins Can Now Edit Permission Handling on Existing ServiceNow Copilot Connectors

Admins previously had to recreate ServiceNow Knowledge and Catalog connector configurations to adopt hierarchical permissions; they can now edit existing connections directly to switch between Simple and Advanced permission handling. MSPs managing ServiceNow-integrated Copilot deployments can now tighten permission models without a disruptive rebuild.

Watermarking Policy Now Available for AI-Generated Video and Audio

A new Cloud Policy service setting lets admins turn on visual or audio watermarks for AI-generated or AI-altered video and audio content in Microsoft 365 (image watermarking remains a separate, user-controlled setting). MSPs advising clients in regulated or reputation-sensitive industries should evaluate turning this on as a low-cost transparency control.

Outlook

No updates worth noting this month.

OneDrive & SharePoint

SharePoint Server Subscription Edition Security Update Ships With 26H1 Feature Update (KB5002873)

The June 9, 2026 cumulative update for SharePoint Server Subscription Edition (build 16.0.19725.20384) patches a large batch of CVEs, including remote code execution and spoofing vulnerabilities, and introduces the SharePoint Server Subscription Edition 26H1 feature update as a baseline for all future public updates. MSPs managing on-premises SharePoint farms should schedule patching now — this replaces the prior KB5002863 update and closes several actively-tracked CVEs. No OneDrive-specific updates were published this period.


July’s list is shorter than June’s, but the shape of the changes matters more than the count: licensing is catching up to the AI push Microsoft has been driving all year, Entra and Purview are both extending governance to AI agents and AI data flows rather than just user identities and user data, and several previews from last month (Entra Backup and Recovery, local AI agent discovery) have already matured toward GA. For MSPs, the through-line is the same one from last month — the AI surface area in Microsoft 365 keeps growing, and the compliance and access-control tooling around it is being built in near-real-time alongside it.

Cover Photo by Christian Wiediger on Unsplash

Author
Gavin Garbutt
Co-Founder & Chairman of Augmentt

FAQ

Using our GDAP tool & Magic Link, setting up is easy! You can integrate with your CSP partner portal in minutes
Augmentt uses a combination of Microsoft Secure Score best practices as well as industry standards such as NIST & CIS. You can use the out of box templates to get started right away and even build your own custom templates to match your client requirements.
Out of box, Augmentt comes pre-configured to not be noisy. Very few Microsoft alerts are critical in nature so you will be receiving tickets for account breaches and not minor user log related events. That said, everything is customizable and you can turn alerts on & off to match your clients’ needs.
No. You can choose to schedule alerts to any stakeholder you want and at the frequency you want or manually download reports when you need them.
Regardless of how MFA is managed across your tenants, we have you covered. Augmentt supports Conditional Access Policies, Security Defaults, Entra ID per user (Legacy) MFA as well as 3rd party MFA services like DUO.
No. You can use Augmentt to monitor and manage all clients regardless of their licensing. For environments with no premium licensing you can still provide alerts and monitoring for account breaches and configure security best practices. For environments with premium licensing, you can leverage Microsoft’s premium alerts and premium security configurations such as Conditional Access Policies.
Augmentt is one of the few vendors SOC 2 Type II, and GDPR compliant.
Site licenses to make sure you can deliver standardized service across all clients very affordably.

SUBSCRIBE for more resources

Related Content

Policy Sprawl Is Killing MSP Efficiency
Policy sprawl is quietly draining your margins, creating security gaps, and eroding client trust. The good news? Standardization is the cure.
Does Microsoft Secure Score Tell the Whole Story?
Do you have a complete understanding of your security? See why MSPs need to understand the role licensing plays in Secure Score results.
Top 10 M365 Security Best Practices for MSPs
Here are the top M365 security best practices to help you enhance protection, ensure compliance, and stay ahead of emerging threats.