Skip to main content

M365 Roundup, August 2026: Sharing Links Stop Granting Access by Default

Nick Ross11 min read

TL;DR

  • The third-generation Microsoft 365 sharing experience introduces a hero link that defaults to Only people added to the file, so the link itself grants access to nobody, rolling out mid-September 2026 through late October 2026.
  • A new SharePoint admin center report gives item-level visibility into every file exposed through the Everyone and Everyone except external users groups, rolling out in August 2026.
  • Microsoft Entra users can register a passkey or passwordless sign-in as their first multifactor authentication method, removing the step that pushed people onto SMS and voice first.
  • Exchange Web Services retirement begins October 1, 2026 and completes April 1, 2027, moving cross-tenant Free/Busy, MailTips, and Calendar Sharing onto Cross-Tenant Access Policy.
  • Support for the legacy Intune app protection targeting setting ends January 11, 2027, and the legacy configuration must stay in place until the replacement assignment filter is assigned.

August 2026 was the month Microsoft went after oversharing from two directions at once. One change makes the default share link grant access to nobody. The other finally shows admins, at the item level, exactly what those old Everyone permissions exposed. Entra also removed the step that quietly pushed users onto SMS before they could set up a passkey, and there is a retirement calendar worth transcribing into your PSA. Here is the month, grouped by what we would work on first.

Sharing gets a new default, and it is the safe one

Microsoft 365 apps logo

Microsoft is rolling out the third-generation Microsoft 365 sharing experience, built around a new hero link: a single sharing link that controls access to a file or folder. Users get one consistent sharing experience whether they copy a link, share through email, or use the browser URL. Because the hero link consolidates sharing controls into one link that can be updated after it has been shared, access changes no longer mean creating and resending a new link.

The part that matters for posture: by default, the hero link is set to Only people added to the file, meaning the link itself does not grant access to anyone. Anyone who has cleaned up a tenant full of Anyone-with-the-link URLs will recognize what a different starting position that is.

Full announcement: Simple, smart, and secure: the next step in sharing files in Microsoft 365 (opens in new tab).

The new hero link sharing experience in Microsoft 365

Rollout: mid-September 2026, previously late August, through late October 2026.

SharePoint shows what "Everyone except external users" actually exposed

A new report in the SharePoint admin center provides detailed, item-level visibility into permissions granted through the Everyone and Everyone except external users special SharePoint groups. Administrators can identify the specific files and items exposed through those permissions across SharePoint and OneDrive.

Those two groups are the classic source of accidental tenant-wide access, and until now the honest answer to "what did that group expose?" involved scripting. This is the report that turns an assumption into evidence.

SharePoint admin center report on Everyone except external users permissions

Rollout: early August 2026, expected to complete in mid-August 2026.

OneDrive on macOS gets a native sync engine

Microsoft is introducing a new Native Sync Engine for OneDrive on macOS, improving sync speed, reliability, and resource efficiency. Details in Making Mac OneDrive faster and more reliable (opens in new tab).

Rollout: early September 2026, previously late August, expected to complete by late November 2026.

Passwordless stops asking users to set up a weaker method first

Microsoft Entra ID logo

A passkey can be the first method a user registers

Users will soon be able to register a passkey as their first multifactor authentication method. Previously, people had to set up an alternate MFA method such as SMS or voice before they could add a passkey (FIDO2), Windows Hello for Business, or macOS Platform SSO. That extra step pushed users toward weaker methods and slowed the move to phishing-resistant sign-in. Now password-only users can go straight to a passkey. Microsoft is also enabling Authenticator App passwordless sign-in as a user's first registered MFA method.

Read this one next to the SMS and voice MFA retirement timeline. The registration order was one of the reasons SMS enrollment stayed so sticky, and removing it changes what a clean passkey rollout looks like.

Rollout: Phase 1 covers synced passkeys, Microsoft Entra passkeys on Windows, and FIDO2 security keys, with general availability (Worldwide, GCC) beginning mid-October 2026 and expected to complete by mid-November 2026. Phase 2 covers Windows Hello for Business, macOS Platform SSO, the Authenticator App passkey, and Authenticator App passwordless sign-in, with general availability beginning in early January and expected to complete by late February 2027.

Windows Hello and macOS Platform SSO count as MFA on their own

Today, Windows Hello for Business and macOS Platform SSO can satisfy MFA requirements during primary sign-in, but users may still be required to register and use an additional passkey or authentication method for certain step-up authentication prompts, Authentication Strength policies, and sign-in frequency checks. After this rollout, users who authenticate with WHfB or macOS PSSO can satisfy supported MFA requirements without registering an additional passkey.

Rollout: early October 2026, expected to complete in late November 2026.

Guests can use passkeys issued by your tenant

Microsoft Entra ID will support passkey registration and sign-in for B2B users, including internal guest users and external users. Eligible B2B users will be able to register and use passkeys issued by the resource tenant to satisfy that tenant's MFA requirements. Guest identities have been the standing exception in most phishing-resistant rollouts, so this closes a real gap.

Rollout: early October 2026, expected to complete by late February 2027.

Teams gains the reporting surfaces admins have been asking for

Microsoft Teams logo

Meeting participants can report suspicious activity

A new Report a meeting capability allows meeting participants to report suspicious, malicious, or potentially fraudulent activity directly from Teams meetings. Information about user-submitted reports is available in the Teams admin center under Protection reports > User-reported security submissions.

Reporting a security concern from a Microsoft Teams meeting

Rollout: early October 2026.

One pane for meeting and call troubleshooting

The Teams admin center is launching a single pane for monitoring and troubleshooting meetings and calls organization-wide. Admins can view in-progress and completed meetings, identify issues, use detailed diagnostics, apply filters, export data, and use Microsoft 365 Copilot for analysis. After rollout, a new Meetings experience appears in the Teams admin center under Meetings & Calls.

To reach it, navigate to Teams admin center > Meetings & Calls > Meetings or Calls.

Single pane meeting and call monitoring in the Teams admin center

Rollout: late September 2026, expected to complete by mid-October 2026.

Admins can configure a mandatory pre-meeting consent experience in the Teams admin center, which helps organizations meet compliance and regulatory requirements by ensuring attendees acknowledge custom terms or disclaimers before joining meetings. Recording notices and responsible AI usage guidelines are the obvious first two uses.

Configuring mandatory participant consent in the Teams admin center
Participant view of the pre-meeting consent prompt in Microsoft Teams

Rollout: mid-October 2026, expected to complete by mid-November 2026.

Live captions move into a right-side panel

This update introduces a new right-side panel layout for live captions and consolidates caption settings into a single menu.

New right-side panel layout for live captions in Microsoft Teams

Rollout: mid-September 2026, expected to complete by mid-September 2026.

Endpoint work: unattended Remote Help and registry-level inventory

Microsoft Intune logo

Remote Help can sign in without the user present

A new capability lets helpdesk staff remotely access physical Windows devices by signing in with credentials they have access to, without requiring the user to grant access or even be logged in. That is genuinely useful for after-hours work, and it is also a privileged capability worth scoping deliberately before it reaches every technician. Details in Remote Help on Windows: unattended support with Remote Sign-In is here (opens in new tab).

Remote Help unattended remote sign-in on Windows

Rollout: generally available.

Device inventory now includes Windows registry data

With Microsoft Intune's July (2607) release, device inventory includes Windows registry data, helping IT admins verify a device's actual configuration rather than only the policy assigned to it. That distinction is the whole problem with assuming compliance from policy assignment. Details in Registry Inventory in Microsoft Intune (opens in new tab).

Windows registry data in Microsoft Intune device inventory

Rollout: generally available.

Retirements and hard dates worth transcribing

Microsoft 365 admin logo

EWS retirement moves cross-tenant calendar features to Cross-Tenant Access Policy

Exchange Web Services in Exchange Online begins retiring October 1, 2026, with full retirement by April 1, 2027. Several cross-tenant collaboration features, specifically Free/Busy, MailTips, and Calendar Sharing, currently use EWS under the hood. As EWS retires, the mechanism carrying those cross-tenant requests has to move somewhere else, and that somewhere is Microsoft 365 Cross-Tenant Access Policy, which replaces the EWS-based approach.

Full announcement: Cross-tenant Free/Busy, MailTips, and Calendar Sharing are moving to Cross-Tenant Access Policy (opens in new tab).

Intune's legacy app protection targeting ends January 11, 2027

Starting January 11, 2027, or soon after, Microsoft is ending support for the legacy Intune app protection policy setting Target to apps on all device types. Policies should be updated to use assignment filters instead. Using the legacy targeting setting can take precedence over assignment filters, producing policy targeting behavior that does not match what the admin expects.

One caveat to respect: to prevent gaps in policy enforcement, do not remove or disable the legacy targeting configuration until the new assignment filter has been assigned to the policy. Microsoft's assignment filters overview (opens in new tab) covers how to build them.

Teams live chat is going away

Starting in August 2026, new customers can no longer set up Microsoft Teams live chat. Starting in October 2026, Teams live chat is no longer supported and stops relaying customer chat messages from websites to Teams. Anyone using it as a website support channel needs a replacement before October.

Teams to Google Calendar sync retires in October 2026

Microsoft is retiring calendar syncing between Microsoft Teams and Google Workspace. After the retirement, organizations can no longer synchronize calendars between the two services using the calendar sync capability available through the Admin app in Teams.

Rollout: October 2026.

Copilot Studio billing starts for GitHub Copilot harness agents

Beginning September 1, 2026, the grace period ends for existing agents and workflows built using the GitHub Copilot harness in Copilot Studio. Those agents and workflows begin consuming Copilot Credits under the usage-based billing model. If anyone in your client base built something on that harness during the grace period, September is when it shows up on the bill.

Outlook and Exchange: more mailbox, easier calendar

Exchange Online logo

Business suites pick up a 100 GB mailbox entitlement

Microsoft 365 Business Basic, Business Standard, and Business Premium now include an additional 50 GB of primary email storage for eligible users. Details in Understanding the new 100 GB mailbox entitlement for Microsoft 365 Business suites (opens in new tab).

The new 100 GB mailbox entitlement for Microsoft 365 Business suites

Rollout: June through September 2026.

An Events filter for the inbox

Outlook is adding an Events filter to help users quickly find calendar invitations and event-related messages.

Rollout: late August 2026, expected to complete by late September 2026.

Drag and drop to reschedule a calendar event

Outlook is introducing drag-and-drop support for calendar events, letting users reschedule an event by moving it to a different time slot on the calendar.

Dragging a calendar event to a new time slot in Outlook

Rollout: mid-August 2026, expected to complete by late August 2026.

Copilot keeps expanding, and so does its surface area

Microsoft Copilot logo

Self-serve connectors let users sync their own external data

Microsoft 365 Copilot now offers self-serve connectors, allowing users to securely sync external data such as Jira and Confluence using their own credentials. Administrators control connector availability and rollout, which is the control to review before this lands rather than after. The feature improves information discovery in Copilot Chat and Microsoft Search.

Self-serve connectors in Microsoft 365 Copilot

Rollout: mid-September 2026, expected to complete by mid-October 2026.

Users can share either an entire Copilot chat session or an individual Copilot response by creating a link that can be shared with others in the same organization.

Sharing a Copilot session or response by link

Rollout: late August 2026, expected to complete by early September 2026.

Ask Copilot in Teams pulls the message in as context

From a specific message or selected text, users can open the existing Copilot pane with the relevant content automatically included as context, removing the need to copy, paste, or manually describe the conversation.

Ask Copilot in Microsoft Teams with message context included

Rollout: late August 2026, expected to complete by late September 2026.

Outlook drafts appear inside Copilot Chat on mobile

When Copilot detects an email-writing intent, it displays an embedded Outlook draft within Copilot Chat. Users can review the drafted content and open the draft directly in Outlook Mobile to edit and send.

Embedded Outlook draft inside Copilot Chat on mobile

Rollout: mid-August 2026, expected to complete by mid-September 2026.

Cowork adds effort control to the model picker

Microsoft Copilot Cowork now lets users select effort levels (Light, Medium, High) in the model picker to control response quality, speed, and usage.

Effort level selection in the Copilot Cowork model picker

Rollout: late August 2026, expected to complete by late August 2026.

PowerPoint gains an interactive slide skill

A new Copilot skill helps users create interactive, full-slide visuals that explain complex concepts, timelines, comparisons, systems, and data.

Interactive slide creation with Copilot in PowerPoint

Rollout: Frontier (Worldwide), available now.

Copilot consolidates into a single app

Like other Microsoft 365 apps, Copilot is moving to a single app experience across personal and work accounts. Users see clearer visual indicators showing which account they are signed into, the app adopts a simpler name and icon, and the web app URL aligns more closely to Copilot. Security, compliance, privacy, and enterprise controls remain unchanged.

The consolidated Microsoft 365 Copilot app experience

Rollout: worldwide rollout for Windows and Mac apps begins mid-September 2026.

A refreshed Copilot experience in Outlook and Teams

Users see a refreshed Copilot experience in Microsoft Outlook and Teams that aligns with the updated, chat-centered experience in the Copilot app.

Refreshed chat-centered Copilot experience in Outlook
Refreshed chat-centered Copilot experience in Microsoft Teams

Rollout: September 2026.

Frontier users get personalized Copilot suggestions

As part of Copilot WorkIQ personalization capabilities, eligible users in the Frontier program may see contextual suggestions in Copilot Chat that highlight prompts and scenarios related to their work activities and patterns.

Rollout: mid-August 2026.

Admin center, Defender, and Purview

Defender XDR unifies the identity timeline

The updated timeline on the Identity page normalizes activity from integrated Microsoft security products, including Microsoft Entra sign-ins, Microsoft Graph audit events, SaaS cloud activity, and device logons. Additional investigation context, filtering, and event details help analysts understand identity-related activity and security risks more quickly. For anyone who has assembled an identity incident timeline from four separate exports, this is the consolidation worth checking first.

Rollout: mid-September 2026, expected to complete by mid-October 2026.

Agents become manageable across tenants

Partners and enterprise administrators can view and manage agents across their managed tenants from the Microsoft 365 admin center. Details in Manage agents across multiple tenants (opens in new tab).

Multi-tenant agent management in the Microsoft 365 admin center

Rollout: Public Preview early August 2026, expected to complete by mid-August 2026.

Purview adaptive scopes get lifecycle status controls

Microsoft Purview is introducing lifecycle status controls for adaptive scopes, evaluating only active recipients and site owners by default. Administrators can include inactive or soft-deleted users when they need to.

Lifecycle status evaluation controls for Purview adaptive scopes

Rollout: mid-October 2026, expected to complete in mid-November 2026.

50% off the Purview Suite for Business Premium

Microsoft is offering 50% off enhanced data protection on the Microsoft Purview Suite for Business Premium. Customers qualify by licensing Business Premium together with Microsoft 365 Copilot Business or Microsoft 365 Copilot, and the offer runs through December 31, 2026. As clients adopt Microsoft 365 Copilot, data security, protection, and governance stop being optional, and this offer makes Purview an easier line item to defend in a Copilot deployment conversation.

Full announcement: Partner Center announcements, August 2026 (opens in new tab).

A safer default only helps the tenants that receive it

The hero link changes what a new share link does. It does not touch the links already out there, and it does not tell you which tenants still have Everyone except external users granting access to something sensitive. That part is still an audit, repeated across every client, every month Microsoft ships another default.

CloudCapsule scans each tenant you manage in about 60 seconds against 250+ controls, with remediation and policy management built in so fixes deploy from one portal instead of five admin centers.

CloudCapsule automated security assessment dashboard

Frequently asked questions

What is the hero link in the new Microsoft 365 sharing experience?

It is a single sharing link that controls access to a file or folder, and it stays the same link whether someone copies it, shares it through email, or grabs the browser URL. Because the link can be updated after it has been shared, access changes no longer require creating and resending a new link. By default it is set to Only people added to the file, which means the link on its own grants access to nobody.

What do we need to do before Exchange Web Services retires?

Cross-tenant Free/Busy, MailTips, and Calendar Sharing currently run on EWS under the hood, and EWS in Exchange Online starts retiring October 1, 2026 with full retirement by April 1, 2027. Those features move to Microsoft 365 Cross-Tenant Access Policy, so any tenant pairing that relies on cross-tenant calendar visibility needs a Cross-Tenant Access Policy configuration before the EWS path stops carrying the requests.

Can we remove the legacy Intune app protection targeting setting now?

Not until the replacement is in place. Microsoft is explicit that removing or disabling the legacy Target to apps on all device types configuration before the new assignment filter has been assigned to the policy creates a gap in policy enforcement. Assign the filter first, then retire the legacy setting.

Who qualifies for the 50% discount on the Microsoft Purview Suite?

Customers who license Microsoft 365 Business Premium together with Microsoft 365 Copilot Business or Microsoft 365 Copilot. The offer covers enhanced data protection on the Microsoft Purview Suite for Business Premium and is available through December 31, 2026.

New sharing defaults only help the tenants that get them applied

CloudCapsule checks every tenant you manage against 250+ controls in about 60 seconds, then deploys the fixes from one portal, so a permission left open in one client does not wait for an audit to surface.

Run a free scan
Nick Ross

Written by

Nick Ross

CEO · Microsoft MVP · Founder, T-Minus 365

Nick is not just a CEO, he's a respected thought leader and influencer in the MSP space. Tens of thousands of MSPs learn through his YouTube channel, T-Minus365. Nick has been honored as a three-time Microsoft MVP for his educational content; his expertise and influence are the backbone of our mission, ensuring that you are in the best hands when it comes to security.

Nick joined Pax8 in 2017, where he would ultimately oversee product management for PSA and Microsoft integrations. Following his tenure at Pax8, Nick has continued to demonstrate his leadership prowess as an executive at various MSPs, culminating in his most recent role at Sourcepass.

Nick holds a Bachelor's Degree in Business Management from Florida State University, as well as a Minor Degree in Entrepreneurship. In his free time, Nick is an avid hiker, reader, and fitness-junkie.

Keep reading