M365 Roundup, September 2026: Copilot Spending Gets Guardrails and Four Deadlines Land Before Year End
TL;DR
- Organizations using the MemberOf rule operator in Entra dynamic groups, dynamic administrative units, or entitlement management auto-assignment policies must replace those configurations by November 3, 2026.
- Starting November 2, 2026, new Microsoft 365 Copilot Business licenses bought through CSP include usage-based billing by default, with pay-as-you-go as the default configuration.
- Intune is moving Windows Health Attestation compliance evaluation from Device Health Attestation to Microsoft Azure Attestation by the end of Q1 2027, and tenants that block the required Azure Attestation endpoints will see compliance evaluation issues.
- Teams will obscure images containing QR codes from external senders by default starting mid-October 2026, and users must choose to reveal the image before scanning.
- Copilot Cost Management spending policies now auto-apply to newly released usage-based Copilot services and agents, and that setting is on by default for every policy.
Most of September's changes can wait for a quarterly review. A handful cannot. Entra has a hard stop for a preview feature some tenants quietly built production groups on, Intune needs firewall work before a compliance migration, and Copilot Business licenses sold through CSP change their default billing in November. Around those deadlines, Microsoft kept building out cost and access controls for Copilot, which is where we would spend the rest of the month's attention.
Which September changes come with a deadline?
MemberOf dynamic rules must be gone by November 3, 2026
The Public Preview of the MemberOf rule operator in Microsoft Entra ID is ending. If you used MemberOf in dynamic groups, dynamic administrative units, or entitlement management auto-assignment policies, replace those configurations by November 3, 2026. Microsoft's reasoning is worth passing on to clients: during the preview it observed MemberOf affecting dynamic membership processing across the whole tenant, so it was never recommended for production use. Migration guidance lives in Migrate before the preview ends (opens in new tab).

Deadline: November 3, 2026.
Intune Health Attestation moves to Microsoft Azure Attestation
Intune will migrate Windows Health Attestation compliance evaluation from the current Device Health Attestation (DHA) service to Microsoft Azure Attestation (MAA). Any Windows compliance policy that relies on Health Attestation signals is affected, and Microsoft says action is required to avoid interruption. If a client's network does not allow the required Azure Attestation endpoints, Health Attestation based compliance evaluation will break once the migration completes. The endpoint list is in Migrating Device Health Attestation compliance policies to Microsoft Azure Attestation (opens in new tab).
Rollout: end of Q1 2027.
The standalone Whiteboard apps retire October 16, 2026
Microsoft is retiring the standalone Whiteboard applications for Windows, iOS, and Android. Beginning October 16, 2026, they are no longer supported for work or school accounts or for personal Microsoft accounts. Users should move to Whiteboard inside Microsoft Teams and the supported web experiences. Details in Whiteboard Standalone App Retirement (opens in new tab).
Retirement: October 16, 2026.
New Copilot Business licenses default to usage-based billing
Starting November 2, 2026, new Microsoft 365 Copilot Business licenses purchased through Cloud Solution Provider (CSP) include usage-based billing by default. Pay-as-you-go becomes the default billing configuration so customers can reach eligible usage-based experiences, including Copilot Cowork, Work IQ APIs, and GitHub Copilot Harness, with less billing setup.
For CSP partners, a default of pay-as-you-go means consumption charges can show up on a client's bill without anyone opting in. Pair this with the Cost Management controls further down before November.
Effective: November 2, 2026.
What changed on the security side?
Teams hides QR codes from external senders
To cut down on phishing and fraud, Teams will obscure images containing QR codes from external senders by default. Users can reveal the image before they view or scan the code. QR phishing has been a steady problem in email, and this brings a similar speed bump to chat.

Rollout: mid-October 2026, expected to complete in mid-October 2026.
Meeting participants can report suspicious activity, and lobby visibility follows admit rights
Microsoft's notice for this item covers two pieces. A new Report a meeting capability lets participants report suspicious, malicious, or potentially fraudulent activity directly from a Teams meeting, and those reports show up in the Teams admin center under Protection reports > User-reported security submissions. Separately, lobby visibility will align with the "Who can admit from lobby" meeting option, so only people who can manage the lobby see who is waiting in it. Microsoft frames this as a more consistent, privacy-focused experience.

Rollout: early September 2026, expected to complete by early October 2026 (previously mid-September).
Conditional Access now governs Outlook attachments
Conditional Access policies are now enforced for Outlook attachment operations. Users who do not meet company policies cannot download, preview, or upload classic attachments, and that includes inline images. If a client has device or location based Conditional Access in place, expect a few "why can't I open this attachment" tickets from users who were previously slipping through.
Rollout: available now.
Secure Score adds four device recommendations aimed at AI-accelerated threats
Microsoft is adding four new Secure Score recommendations in Microsoft Defender for Endpoint to help organizations assess device readiness for AI-accelerated threats. They flag eligible Windows devices missing:
- Trusted Platform Module (TPM) 2.0
- Virtualization-based Security (VBS)
- Hypervisor-Protected Code Integrity (HVCI), also known as Memory Integrity
- Windows Local Administrator Password Solution (LAPS)
Expect Secure Score numbers to move when these land, which is worth explaining to clients before they notice the drop themselves.

Rollout: mid-September 2026, expected to complete by late September 2026.
Defender XDR treats Purview DLP alerts as behaviors by default
Starting October 12, 2026, Microsoft Defender XDR will set Microsoft Purview DLP alerts as behaviors by default. Alert volume drops, and the DLP data stays available in Advanced Hunting and Purview. If you want DLP events to keep generating standard alerts and appearing in the Defender XDR incident queues, disable the rule.
Effective: October 12, 2026.
Integrated Security Operations Center comes to Defender in preview
Integrated Security Operations Center (ISOC) is now in public preview in Microsoft Defender. The ISOC benefit lets eligible Microsoft Defender Suite, Microsoft 365 E5, and E7 customers bring XDR, SIEM, threat intelligence, automation, and AI together in Defender. Read more in Integrated Security Operations Center in Microsoft Defender (opens in new tab) and Reimagining the SOC for the agentic era in Microsoft Defender (opens in new tab).

Rollout: public preview September 23, 2026.
Entra keeps pushing identity management into the cloud
Teams devices sign in without stored passwords
Passwordless Teams Shared Space device resource accounts let a Teams device sign in with a secure, device-bound resource account credential in place of a stored username and password. Setup is in Passwordless Entra resource accounts (opens in new tab).
Status: generally available.
Cloud Sync provisions from Entra ID back into Active Directory
Microsoft Entra Cloud Sync can now provision users, groups, and group memberships from Entra ID down to on-premises Active Directory Domain Services (AD DS). That helps cloud-first organizations manage identities from the cloud while keeping AD-dependent applications working. Admins can provision cloud-native users, SOA-converted users, B2B guests, security groups, and memberships into AD, preserve key identity attributes for continuity, and run lifecycle and access governance through Microsoft Entra ID Governance. Walkthrough in Provision users and groups to AD with Cloud Sync (opens in new tab).
Status: public preview.
Global Secure Access adds an MCP firewall
The Global Secure Access MCP firewall is a network-based, identity-centric control that gives centralized visibility, policy enforcement, and runtime protection for MCP traffic between AI agents and remote MCP servers. If clients are starting to connect agents to outside tools, this is the first Microsoft-native place to see and police that traffic. Configuration steps in Configure the MCP firewall (opens in new tab).

Status: public preview.
How do you keep Copilot spending and access under control?
Copilot Cost Management gets its September update
With usage-based billing becoming the Copilot Business default, this is the set of controls to learn first. The September 2026 update covers:
- Auto-apply new services to spending policies. Spending policies can automatically cover newly released usage-based Copilot services and agents. The Auto-apply new services setting is on by default for every policy, so new services and agents inherit policy coverage as they arrive.
- User limit threshold email alerts. Admins can get email notifications as users approach their spending limits. Admin action: configure threshold percentages and turn on notifications for the relevant policies.
- Wider access to consumption reporting. Consumption dashboards are now available to more read-only roles, including AI Reader, Global Reader, and License Administrator.
- Enhanced consumption reporting. Visibility across Prepaid (P3) and Pay-as-you-Go (PayG) credit usage, plus capacity pack consumption breakdowns across the Microsoft Admin Center (MAC) and Power Platform Admin Center (PPAC). Admin action: review the updated dashboards and your reporting processes.
- Policy-level reporting. Dashboards include a dedicated policy view for analyzing usage and spending by spending policy. No admin action needed.
- Custom approval policies for Cowork credit requests. Admins can build request policies that route Cowork credit requests, and future supported service requests, to alternate approval workflows. Admin action: if you want this, configure routing in the new Request Policies tab in the Credit Requests experience.
- Spending follows users across policies. Consumption now carries over when a user moves between spending policies. A user who has consumed 500 credits under one policy keeps that 500-credit history after moving to another, which stops limits from resetting. No admin action required, though any internal process that relies on moving users between policies deserves a second look.
- Healthy spending policy guidance. Organizations may get recommendations when a policy looks unhealthy or misconfigured on limits and cost guardrails. Admin action: review and update policies when prompted.
Rollout: early September 2026.
Browser Use in Copilot Cowork gets scoped admin control
Browser Use for Copilot Cowork now comes with more granular access controls. Admins can enable the capability for specific users or security groups instead of managing it tenant-wide.

Rollout: mid-September 2026, expected to complete by late September 2026.
Federated Copilot connectors can now write
Federated Copilot connectors already let Microsoft 365 Copilot retrieve data from third-party services in real time. With this update, supported connector tools that create, update, and delete content in those services become available in Copilot experiences. Read access to a connected service and write access to it are different risk conversations, so review which federated connectors a tenant allows before this lands.
Rollout: early October 2026, expected to complete by late October 2026.
SpaceXAI joins as a Copilot subprocessor
SpaceXAI is added as a Microsoft Copilot subprocessor, which brings Grok models to Word, Excel, and PowerPoint for eligible Frontier customers starting September 18, 2026. It arrives with an admin setting, so check where each tenant stands on third-party model subprocessors. Background in Expanding model choice in Copilot with Grok (opens in new tab).

Copilot is rebranded again around Home, Code, and Autopilot
Another round of Copilot rebranding, this time organized around Home, Code, and Autopilot. See Introducing the new Copilot with Home, Code and Autopilot (opens in new tab).
Rollout: rolling out in the Frontier Program now, with no GA timeline yet.
Makers can build apps in Copilot Studio and Copilot Cowork
These experiences turn an idea into an app through natural-language guidance and generative AI. A maker describes what they want, gets a working first draft, refines it, previews and tests it, then publishes and shares it. Apps can use organizational data through whatever connectors your organization's policies permit, which makes connector policy the real control point here.

Rollout: Copilot Cowork begins September 8, 2026, expected to complete by September 14, 2026.
PowerPoint Copilot gets Strict Mode and shared Brand Skills
Strict brand adherence (Strict Mode) lets Brand Managers decide whether Copilot may create new layouts or must stick to approved template and slide master layouts. With it on, Copilot follows the template exactly and does not add or remove placeholders or create new layouts. The same item also covers guiding presentation creation through notes steering.
Status: generally available.
Separately, Brand Managers can upload custom presentation skills as Markdown (.md) files to Brand Kit and share them across the organization for Copilot in PowerPoint. The result is reusable, organization-approved instructions for building presentations.

Rollout: late September 2026, expected to complete by the end of September 2026.
Ask Copilot about selected PDF text on OneDrive for iOS
Select text in any PDF in OneDrive on iOS and tap Ask Copilot to explain, summarize, translate, or ask a custom question about the selection. It matches the in-context Copilot experience already generally available on desktop.

Rollout: rolling out gradually. Microsoft lists expected completion as late March 2026, a date that has already passed, so treat the timing as unconfirmed.
Teams, Outlook, OneDrive, and Intune: the rest of the month
Teams: pause notifications, form triggers, reminders, and transcript filtering
Four smaller Teams changes, none of which need prep but all of which will generate user questions:
Pause all notifications. Users can temporarily pause notifications for a chosen period, which helps with focused work and meetings without touching their existing notification settings.
Rollout: early October 2026, expected to complete by late October 2026.
List Form trigger in Workflows. A new trigger lets organizations automate actions when users submit responses to forms built on SharePoint lists. Individual responses become workflow variables, so a creator can post selected answers to a Teams channel and add more detail as threaded replies.

Rollout: late September 2026, expected to complete by late October 2026.
Personal message reminders. Users can turn chat and channel messages into reminders to track follow-ups.

Rollout: begins and completes in October 2026.
Profanity filtering policy for transcripts. A new meeting policy lets admins control whether profane words are masked in live transcription and saved meeting transcripts.

Rollout: mid-October 2026, expected to complete by late October 2026.
Outlook: hand off a meeting and grow the archive
Change organizer. Users can ask someone else in the organization to become the organizer of an eligible Outlook meeting or recurring series, and ownership only changes after that person accepts. It ships in three phases:
- Phase 1: eligible non-online meetings, late September through late October 2026.
- Phase 2: eligible online meetings. For Teams meetings, the transfer generates a new Teams meeting link owned by the new organizer.
- Phase 3: transfer support for eligible Teams meeting artifacts, including chat, meeting options, transcripts, recordings, agenda, notes, and attendance reports.
Timing for Phases 2 and 3 will be announced separately. This finally solves the "organizer left the company" problem that usually ends in a rebuilt recurring meeting.
Auto-expanding archive grows to 3 TB. Microsoft Purview Data Lifecycle Management raises the maximum auto-expanding archive for eligible Exchange Online archive mailboxes from 1.5 TB to 3 TB, with no manual expansion or support requests needed. Eligible licensing:
- Office 365 E5, A5, and G5
- Microsoft 365 E5, A5, and G5
- Microsoft 365 Purview Suite
- Microsoft 365 Purview Suite FLW, EDU, and GOV
- Microsoft Defender + Purview Suite FLW
- Microsoft 365 F5 Compliance
- Microsoft 365 F5 Security + Compliance
- The eDiscovery & Audit and Insider Risk Management mini suites combined with the Information Protection & Governance mini suite
Rollout: mid-October 2026, expected to complete by late October 2026.
OneDrive and SharePoint: storage costs, archiving, and PDF review
Pay-as-you-go OneDrive storage. A consumption-based billing option for extra OneDrive storage lets selected accounts exceed their licensed quota when needed, while admins control which users can consume storage beyond it. The price is $0.20/GB/month.
Rollout: early November 2026, expected to complete by early December 2026.
Archive SharePoint files under retention policies. Inactive content can move to Microsoft 365 Archive while staying compliant and discoverable, which reduces storage costs. Archived content is also excluded from Copilot indexing, which can make Copilot answers more relevant by focusing them on current, active data. For Copilot readiness work, that makes archiving a relevance lever as well as a cost one.
Rollout: early October 2026 (previously mid-September), expected to complete by early November 2026.
Anchored comments in the PDF viewer. In OneDrive and SharePoint, users can attach a comment to a specific spot on a PDF page or to selected text, then collaborate through replies and @mentions, bringing PDF review in line with commenting in Office documents.
Rollout: mid-October 2026, expected to complete by mid-November 2026.
macOS sync limit rises to 1 million items. OneDrive sync on macOS moves from 300,000 to 1 million items per sync instance, per device, so large OneDrive and SharePoint libraries sync more reliably.
Rollout: early October 2026 (previously mid-September), expected to complete by early November 2026.
Intune: staged rollouts with deployment plans
Deployments in Intune let admins create gradual, controlled, predictable rollouts of Intune payloads such as apps and policies. Rollouts use rings, which are group assignments that progress on specific date and time criteria. Ring-based rollouts are how you avoid pushing a bad policy to every device in a client at once. Overview in Deployment plans and deployments overview in Microsoft Intune (opens in new tab).

Status: public preview.
Where to start this month
If you only get to three things across your client base before November, make them the MemberOf cleanup, the Azure Attestation endpoint check, and a spending policy review for any tenant buying Copilot Business through CSP. Each one touches every tenant differently, which is what makes them slow to do by hand.
CloudCapsule scans each tenant you manage in about 60 seconds, collecting over 250 data points, and now includes remediation and policy management so you can deploy fixes from our portal.

Frequently asked questions
What happens if we still use MemberOf in dynamic groups after November 3, 2026?
The MemberOf rule operator was a Public Preview feature and that preview is ending. Microsoft asks organizations to replace MemberOf-based configurations in dynamic groups, dynamic administrative units, and entitlement management auto-assignment policies by November 3, 2026, and notes it observed MemberOf affecting dynamic membership processing across a tenant, so it was never recommended for production.
Do we need to do anything for the Intune Health Attestation migration?
Yes. Microsoft states action is required. Confirm your network allows access to the Microsoft Azure Attestation endpoints listed in the Intune endpoints documentation. Tenants that block them will have problems with Health Attestation based compliance evaluation once the migration completes at the end of Q1 2027.
What does OneDrive pay-as-you-go storage cost?
$0.20 per GB per month. Admins choose which OneDrive accounts can exceed their licensed storage quota, and the option rolls out from early November 2026 through early December 2026.
Which licenses get the 3 TB auto-expanding archive?
Office 365 E5, A5, and G5; Microsoft 365 E5, A5, and G5; Microsoft 365 Purview Suite; Purview Suite FLW, EDU, and GOV; Microsoft Defender + Purview Suite FLW; Microsoft 365 F5 Compliance; Microsoft 365 F5 Security + Compliance; and the eDiscovery & Audit plus Insider Risk Management mini suites combined with the Information Protection & Governance mini suite.
Find the MemberOf rules and weak devices before the deadline does
CloudCapsule scans each tenant you manage in about 60 seconds across 250+ data points, then lets you deploy remediation and policy fixes from one portal.
Run a free scan
Written by
Nick Ross
CEO · Microsoft MVP · Founder, T-Minus 365
Nick is not just a CEO, he's a respected thought leader and influencer in the MSP space. Tens of thousands of MSPs learn through his YouTube channel, T-Minus365. Nick has been honored as a three-time Microsoft MVP for his educational content; his expertise and influence are the backbone of our mission, ensuring that you are in the best hands when it comes to security.
Nick joined Pax8 in 2017, where he would ultimately oversee product management for PSA and Microsoft integrations. Following his tenure at Pax8, Nick has continued to demonstrate his leadership prowess as an executive at various MSPs, culminating in his most recent role at Sourcepass.
Nick holds a Bachelor's Degree in Business Management from Florida State University, as well as a Minor Degree in Entrepreneurship. In his free time, Nick is an avid hiker, reader, and fitness-junkie.


