M365 Roundup, August 2026: Sharing Links Stop Granting Access by Default
TL;DR
- The third-generation Microsoft 365 sharing experience introduces a hero link that defaults to Only people added to the file, so the link itself grants access to nobody, rolling out mid-September 2026 through late October 2026.
- A new SharePoint admin center report gives item-level visibility into every file exposed through the Everyone and Everyone except external users groups, rolling out in August 2026.
- Microsoft Entra users can register a passkey or passwordless sign-in as their first multifactor authentication method, removing the step that pushed people onto SMS and voice first.
- Exchange Web Services retirement begins October 1, 2026 and completes April 1, 2027, moving cross-tenant Free/Busy, MailTips, and Calendar Sharing onto Cross-Tenant Access Policy.
- Support for the legacy Intune app protection targeting setting ends January 11, 2027, and the legacy configuration must stay in place until the replacement assignment filter is assigned.
August 2026 was the month Microsoft went after oversharing from two directions at once. One change makes the default share link grant access to nobody. The other finally shows admins, at the item level, exactly what those old Everyone permissions exposed. Entra also removed the step that quietly pushed users onto SMS before they could set up a passkey, and there is a retirement calendar worth transcribing into your PSA. Here is the month, grouped by what we would work on first.
Sharing gets a new default, and it is the safe one
One hero link replaces the pile of one-off share links
Microsoft is rolling out the third-generation Microsoft 365 sharing experience, built around a new hero link: a single sharing link that controls access to a file or folder. Users get one consistent sharing experience whether they copy a link, share through email, or use the browser URL. Because the hero link consolidates sharing controls into one link that can be updated after it has been shared, access changes no longer mean creating and resending a new link.
The part that matters for posture: by default, the hero link is set to Only people added to the file, meaning the link itself does not grant access to anyone. Anyone who has cleaned up a tenant full of Anyone-with-the-link URLs will recognize what a different starting position that is.
Full announcement: Simple, smart, and secure: the next step in sharing files in Microsoft 365 (opens in new tab).

Rollout: mid-September 2026, previously late August, through late October 2026.
SharePoint shows what "Everyone except external users" actually exposed
A new report in the SharePoint admin center provides detailed, item-level visibility into permissions granted through the Everyone and Everyone except external users special SharePoint groups. Administrators can identify the specific files and items exposed through those permissions across SharePoint and OneDrive.
Those two groups are the classic source of accidental tenant-wide access, and until now the honest answer to "what did that group expose?" involved scripting. This is the report that turns an assumption into evidence.

Rollout: early August 2026, expected to complete in mid-August 2026.
OneDrive on macOS gets a native sync engine
Microsoft is introducing a new Native Sync Engine for OneDrive on macOS, improving sync speed, reliability, and resource efficiency. Details in Making Mac OneDrive faster and more reliable (opens in new tab).
Rollout: early September 2026, previously late August, expected to complete by late November 2026.
Passwordless stops asking users to set up a weaker method first
A passkey can be the first method a user registers
Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method such as SMS or voice before they could add a passkey (FIDO2), Windows Hello for Business, or macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey. Microsoft is also enabling Authenticator App passwordless sign-in as a user's first registered MFA method.
Read this one next to the SMS and voice MFA retirement timeline. The registration order was one of the reasons SMS enrollment stayed so sticky, and removing it changes what a clean passkey rollout looks like.
Rollout: Phase 1 covers synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys, with general availability (Worldwide, GCC) beginning mid-October 2026 and expected to complete by mid-November 2026. Phase 2 covers Windows Hello for Business, macOS Platform SSO, the Authenticator App passkey, and Authenticator App passwordless sign-in, with general availability beginning in early January and expected to complete by late February 2027.
Windows Hello and macOS Platform SSO count as MFA on their own
Today, Windows Hello for Business and macOS Platform SSO can satisfy MFA requirements during primary sign-in, but users may still be required to register and use an additional passkey or authentication method for certain step-up authentication prompts, Authentication Strength policies, and sign-in frequency checks. After this rollout, users who authenticate with WHfB or macOS PSSO can satisfy supported MFA requirements without registering an additional passkey.
Rollout: early October 2026, expected to complete in late November 2026.
Guests can use passkeys issued by your tenant
Microsoft Entra ID will support passkey registration and sign-in for B2B users, including internal guest users and external users. Eligible B2B users will be able to register and use passkeys issued by the resource tenant to satisfy that tenant's MFA requirements. Guest identities have been the standing exception in most phishing-resistant rollouts, so this closes a real gap.
Rollout: early October 2026, expected to complete by late February 2027.
Teams gains the reporting surfaces admins have been asking for
Meeting participants can report suspicious activity
A new Report a meeting capability allows meeting participants to report suspicious, malicious, or potentially fraudulent activity directly from Teams meetings. Information about user-submitted reports is available in the Teams admin center under Protection reports > User-reported security submissions.

Rollout: early October 2026.
One pane for meeting and call troubleshooting
The Teams admin center is launching a single pane for monitoring and troubleshooting meetings and calls organization-wide. Admins can view in-progress and completed meetings, identify issues, use detailed diagnostics, apply filters, export data, and use Microsoft 365 Copilot for analysis. After rollout, a new Meetings experience appears in the Teams admin center under Meetings & Calls.
To reach it, navigate to Teams admin center > Meetings & Calls > Meetings or Calls.

Rollout: late September 2026, expected to complete by mid-October 2026.
Consent can be mandatory before anyone joins
Admins can configure a mandatory pre-meeting consent experience in the Teams admin center, which helps organizations meet compliance and regulatory requirements by ensuring attendees acknowledge custom terms or disclaimers before joining meetings. Recording notices and responsible AI usage guidelines are the obvious first two uses.


Rollout: mid-October 2026, expected to complete by mid-November 2026.
Live captions move into a right-side panel
This update introduces a new right-side panel layout for live captions and consolidates caption settings into a single menu.

Rollout: mid-September 2026, expected to complete by mid-September 2026.
Endpoint work: unattended Remote Help and registry-level inventory
Remote Help can sign in without the user present
A new capability lets helpdesk staff remotely access physical Windows devices by signing in with credentials they have access to, without requiring the user to grant access or even be logged in. That is genuinely useful for after-hours work, and it is also a privileged capability worth scoping deliberately before it reaches every technician. Details in Remote Help on Windows: unattended support with Remote Sign-In is here (opens in new tab).

Rollout: generally available.
Device inventory now includes Windows registry data
With Microsoft Intune's July (2607) release, device inventory includes Windows registry data, helping IT admins verify a device's actual configuration rather than only the policy assigned to it. That distinction is the whole problem with assuming compliance from policy assignment. Details in Registry Inventory in Microsoft Intune (opens in new tab).

Rollout: generally available.
Retirements and hard dates worth transcribing
EWS retirement moves cross-tenant calendar features to Cross-Tenant Access Policy
Exchange Web Services in Exchange Online begins retiring October 1, 2026, with full retirement by April 1, 2027. Several cross-tenant collaboration features, specifically Free/Busy, MailTips, and Calendar Sharing, currently use EWS under the hood. As EWS retires, the mechanism carrying those cross-tenant requests has to move somewhere else, and that somewhere is Microsoft 365 Cross-Tenant Access Policy, which replaces the EWS-based approach.
Full announcement: Cross-tenant Free/Busy, MailTips, and Calendar Sharing are moving to Cross-Tenant Access Policy (opens in new tab).
Intune's legacy app protection targeting ends January 11, 2027
Starting January 11, 2027, or soon after, Microsoft is ending support for the legacy Intune app protection policy setting Target to apps on all device types. Policies should be updated to use assignment filters instead. Using the legacy targeting setting can take precedence over assignment filters, producing policy targeting behavior that does not match what the admin expects.
One caveat to respect: to prevent gaps in policy enforcement, do not remove or disable the legacy targeting configuration until the new assignment filter has been assigned to the policy. Microsoft's assignment filters overview (opens in new tab) covers how to build them.
Teams live chat is going away
Starting in August 2026, new customers can no longer set up Microsoft Teams live chat. Starting in October 2026, Teams live chat is no longer supported and stops relaying customer chat messages from websites to Teams. Anyone using it as a website support channel needs a replacement before October.
Teams to Google Calendar sync retires in October 2026
Microsoft is retiring calendar syncing between Microsoft Teams and Google Workspace. After the retirement, organizations can no longer synchronize calendars between the two services using the calendar sync capability available through the Admin app in Teams.
Rollout: October 2026.
Copilot Studio billing starts for GitHub Copilot harness agents
Beginning September 1, 2026, the grace period ends for existing agents and workflows built using the GitHub Copilot harness in Copilot Studio. Those agents and workflows begin consuming Copilot Credits under the usage-based billing model. If anyone in your client base built something on that harness during the grace period, September is when it shows up on the bill.
Outlook and Exchange: more mailbox, easier calendar
Business suites pick up a 100 GB mailbox entitlement
Microsoft 365 Business Basic, Business Standard, and Business Premium now include an additional 50 GB of primary email storage for eligible users. Details in Understanding the new 100 GB mailbox entitlement for Microsoft 365 Business suites (opens in new tab).

Rollout: June through September 2026.
An Events filter for the inbox
Outlook is adding an Events filter to help users quickly find calendar invitations and event-related messages.
Rollout: late August 2026, expected to complete by late September 2026.
Drag and drop to reschedule a calendar event
Outlook is introducing drag-and-drop support for calendar events, letting users reschedule an event by moving it to a different time slot on the calendar.

Rollout: mid-August 2026, expected to complete by late August 2026.
Copilot keeps expanding, and so does its surface area
Self-serve connectors let users sync their own external data
Microsoft 365 Copilot now offers self-serve connectors, allowing users to securely sync external data such as Jira and Confluence using their own credentials. Administrators control connector availability and rollout, which is the control to review before this lands rather than after. The feature improves information discovery in Copilot Chat and Microsoft Search.

Rollout: mid-September 2026, expected to complete by mid-October 2026.
Copilot sessions and individual responses become shareable links
Users can share either an entire Copilot chat session or an individual Copilot response by creating a link that can be shared with others in the same organization.

Rollout: late August 2026, expected to complete by early September 2026.
Ask Copilot in Teams pulls the message in as context
From a specific message or selected text, users can open the existing Copilot pane with the relevant content automatically included as context, removing the need to copy, paste, or manually describe the conversation.

Rollout: late August 2026, expected to complete by late September 2026.
Outlook drafts appear inside Copilot Chat on mobile
When Copilot detects an email-writing intent, it displays an embedded Outlook draft within Copilot Chat. Users can review the drafted content and open the draft directly in Outlook Mobile to edit and send.

Rollout: mid-August 2026, expected to complete by mid-September 2026.
Cowork adds effort control to the model picker
Microsoft Copilot Cowork now lets users select effort levels (Light, Medium, High) in the model picker to control response quality, speed, and usage.

Rollout: late August 2026, expected to complete by late August 2026.
PowerPoint gains an interactive slide skill
A new Copilot skill helps users create interactive, full-slide visuals that explain complex concepts, timelines, comparisons, systems, and data.

Rollout: Frontier (Worldwide), available now.
Copilot consolidates into a single app
Like other Microsoft 365 apps, Copilot is moving to a single app experience across personal and work accounts. Users see clearer visual indicators showing which account they are signed into, the app adopts a simpler name and icon, and the web app URL aligns more closely to Copilot. Security, compliance, privacy, and enterprise controls remain unchanged.

Rollout: worldwide rollout for Windows and Mac apps begins mid-September 2026.
A refreshed Copilot experience in Outlook and Teams
Users see a refreshed Copilot experience in Microsoft Outlook and Teams that aligns with the updated, chat-centered experience in the Copilot app.


Rollout: September 2026.
Frontier users get personalized Copilot suggestions
As part of Copilot WorkIQ personalization capabilities, eligible users in the Frontier program may see contextual suggestions in Copilot Chat that highlight prompts and scenarios related to their work activities and patterns.
Rollout: mid-August 2026.
Admin center, Defender, and Purview
Defender XDR unifies the identity timeline
The updated timeline on the Identity page normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS cloud activity, and device logons. Additional investigation context, filtering, and event details help analysts understand identity-related activity and security risks more quickly. For anyone who has assembled an identity incident timeline from four separate exports, this is the consolidation worth checking first.
Rollout: mid-September 2026, expected to complete by mid-October 2026.
Agents become manageable across tenants
Partners and enterprise administrators can view and manage agents across their managed tenants from the Microsoft 365 admin center. Details in Manage agents across multiple tenants (opens in new tab).

Rollout: Public Preview early August 2026, expected to complete by mid-August 2026.
Purview adaptive scopes get lifecycle status controls
Microsoft Purview is introducing lifecycle status controls for adaptive scopes, evaluating only active recipients and site owners by default. Administrators can include inactive or soft-deleted users when they need to.

Rollout: mid-October 2026, expected to complete in mid-November 2026.
50% off the Purview Suite for Business Premium
Microsoft is offering 50% off enhanced data protection on the Microsoft Purview Suite for Business Premium. Customers qualify by licensing Business Premium together with Microsoft 365 Copilot Business or Microsoft 365 Copilot, and the offer runs through December 31, 2026. As clients adopt Microsoft 365 Copilot, data security, protection, and governance stop being optional, and this offer makes Purview an easier line item to defend in a Copilot deployment conversation.
Full announcement: Partner Center announcements, August 2026 (opens in new tab).
A safer default only helps the tenants that receive it
The hero link changes what a new share link does. It does not touch the links already out there, and it does not tell you which tenants still have Everyone except external users granting access to something sensitive. That part is still an audit, repeated across every client, every month Microsoft ships another default.
CloudCapsule scans each tenant you manage in about 60 seconds against 250+ controls, with remediation and policy management built in so fixes deploy from one portal instead of five admin centers.

Frequently asked questions
What is the hero link in the new Microsoft 365 sharing experience?
It is a single sharing link that controls access to a file or folder, and it stays the same link whether someone copies it, shares it through email, or grabs the browser URL. Because the link can be updated after it has been shared, access changes no longer require creating and resending a new link. By default it is set to Only people added to the file, which means the link on its own grants access to nobody.
What do we need to do before Exchange Web Services retires?
Cross-tenant Free/Busy, MailTips, and Calendar Sharing currently run on EWS under the hood, and EWS in Exchange Online starts retiring October 1, 2026 with full retirement by April 1, 2027. Those features move to Microsoft 365 Cross-Tenant Access Policy, so any tenant pairing that relies on cross-tenant calendar visibility needs a Cross-Tenant Access Policy configuration before the EWS path stops carrying the requests.
Can we remove the legacy Intune app protection targeting setting now?
Not until the replacement is in place. Microsoft is explicit that removing or disabling the legacy Target to apps on all device types configuration before the new assignment filter has been assigned to the policy creates a gap in policy enforcement. Assign the filter first, then retire the legacy setting.
Who qualifies for the 50% discount on the Microsoft Purview Suite?
Customers who license Microsoft 365 Business Premium together with Microsoft 365 Copilot Business or Microsoft 365 Copilot. The offer covers enhanced data protection on the Microsoft Purview Suite for Business Premium and is available through December 31, 2026.
New sharing defaults only help the tenants that get them applied
CloudCapsule checks every tenant you manage against 250+ controls in about 60 seconds, then deploys the fixes from one portal, so a permission left open in one client does not wait for an audit to surface.
Run a free scan
Written by
Nick Ross
CEO · Microsoft MVP · Founder, T-Minus 365
Nick is not just a CEO, he's a respected thought leader and influencer in the MSP space. Tens of thousands of MSPs learn through his YouTube channel, T-Minus365. Nick has been honored as a three-time Microsoft MVP for his educational content; his expertise and influence are the backbone of our mission, ensuring that you are in the best hands when it comes to security.
Nick joined Pax8 in 2017, where he would ultimately oversee product management for PSA and Microsoft integrations. Following his tenure at Pax8, Nick has continued to demonstrate his leadership prowess as an executive at various MSPs, culminating in his most recent role at Sourcepass.
Nick holds a Bachelor's Degree in Business Management from Florida State University, as well as a Minor Degree in Entrepreneurship. In his free time, Nick is an avid hiker, reader, and fitness-junkie.


