Microsoft 365 June 2026 Roundup: What Shipped, What's Next

Issue #002 17 June 2026, Monthly Update Tracker

What shipped in Microsoft 365 in the first half of June 2026, plus the deadlines, defaults and Preview to GA transitions admins should be preparing for in late June and July. Scan the timeline. Bookmark for the next issue.

30+Signals tracked
6Key deadlines
3Default changes
6Pillars
The Five That Matter
  1. Microsoft Sentinel is moving into the Defender portal on 1 July. Automatic redirect for users still on the Azure portal, new Sentinel environments only in the Defender portal. The full Azure portal UI retires 31 March 2027, but day-to-day SecOps moves next month. Update runbooks, RBAC and SOAR endpoints in the next two weeks.
  2. Three Conditional Access enforcement changes converge across May, June and July. Improved enforcement for All-resources policies with resource exclusions started rolling out from 13 May and continues through the June window; "Require approved client app" goes read-only on 30 June; credential registration evaluation expands to Windows Hello for Business and macOS Platform SSO on 6 July. Verify report-only logs ahead of each step.
  3. Agent 365 expands across Defender, Intune and Windows 365. Public previews this month for context mapping in Defender, runtime blocking for OpenClaw via Intune, registry sync with AWS Bedrock and Google Cloud, and Windows 365 for Agents (US preview only). Agent governance is now a tenant-wide conversation, not just a Copilot Studio one.
  4. Microsoft 365 Copilot got a visible redesign plus agentic capabilities in Word, Excel and PowerPoint. End users will notice. Notebooks expand to Copilot Chat tier and can now ground on individual Teams meetings (transcripts, notes, chats, shared content). Update change-management material now.
  5. Work IQ API is GA and billing through Copilot Credits. Custom agents and third-party AI platforms can now ground on Microsoft 365 data with governance enforced at the API layer. Charges flow back to the tenant. Finance needs the heads-up before makers scale.
Impact Admin action Security User-facing Licensing Watch only
1 Jun
Prerequisite change
Admin & Commerce Licensing

Validate per tenantAgent 365 licensing and prerequisites need tenant-by-tenant validation

Agent 365 is available through Microsoft 365 E7 and may also be available through standalone or add-on licensing depending on tenant eligibility, programme and commercial terms. Because packaging and prerequisites are evolving, do not assume coverage from a lower SKU or from a previous quote. Validate the current terms with Microsoft Product Terms, the customer's CSP / partner and the tenant's actual eligibility before designing the rollout.

Action: confirm the current Agent 365 quote line, prerequisites and eligible base licences with the CSP / partner before including Agent 365 in a project scope or budget.

Admin & Commerce Licensing

Billing rollingMicrosoft 365 E7 commerce cycles reflect the 1 May GA

Microsoft 365 E7 went GA on 1 May and bundles Microsoft 365 E5-level productivity / security capabilities with Microsoft 365 Copilot, Agent 365 and advanced identity / security capabilities. June is one of the first practical commercial planning windows after the 1 May GA for customers comparing their existing E5 + Copilot + Agent 365 + Entra Suite stack against Microsoft 365 E7. If E7 is on the renewal radar, this is the right moment to map the existing stack against E7 list before the next renewal cycle locks in.

2 Jun
Preview
Admin & Commerce Admin action

PreviewPower Platform inventory shows connector footprint per resource

A new connectors column rolls out across canvas apps, model-driven apps, cloud flows, agent flows and agents, letting admins see at a glance which connectors each resource calls. Public preview from 2 June. Pairs well with the Advanced Connector Policies GA later in the month for governance teams responsible for the maker estate.

9 Jun
Patch Tuesday
Endpoints & Intune Admin action

KB5094126Windows 11 June cumulative update: desktop.ini hardening

The June Patch Tuesday update introduces security hardening for the processing of desktop.ini in content downloaded from remote locations. The side effect known so far: some users see missing custom folder icons or localised folder names. Test against your standard images before broad deployment, especially in environments that rely on branded folder icons or localised file shares.

Action: confirm pilot ring sees no regression in branded / localised folder rendering before broad ring opens. Link KB to the change ticket.

11 Jun
Preview to GA
Admin & Commerce Admin action

GAPower Platform Advanced Connector Policies (ACP) generally available

ACP is GA, giving admins finer control over which connectors and which connector operations can run in which environments. Material for tenants with a sizeable maker community across multiple environments; pairs with the new connectors-column inventory preview from 2 June. Worth a fresh look at existing DLP connector policies before rolling out the more granular ACP rules.

Action: inventory current connector DLP groupings; identify where ACP gives meaningful enforcement value over what DLP groups already cover.

May–Jun
Rollout window
Identity & Access Security

Rolling outConditional Access improved enforcement for All-resources policies with exclusions

Microsoft Entra ID started rolling out improved enforcement for Conditional Access policies targeting All resources with resource exclusions from 13 May 2026, with rollout continuing through the June window. Tenants with policies that relied on the older exclusion behaviour may see previously masked blocks, MFA prompts or session controls.

Action: filter the Conditional Access tenant for any All-resources policy with exclusions, review sign-in logs / report-only impact, and confirm sign-ins to previously excluded scopes still behave as expected.

15 Jun
Retirement
Security & Compliance Admin action

Retires 15 JunMicrosoft Sentinel Repositories REST API: older versions retired

Source Control actions using older Sentinel Repositories REST API versions stop working from 15 June. CI / CD pipelines and infrastructure-as-code wiring that pushes Sentinel content packs through Git must be on the current API surface. The break tends to surface during the next pipeline run rather than instantly.

Action: grep the IaC repo and Git-backed Sentinel content pipelines for old API versions; pin to current ones in the deployment definitions.

16 Jun
Preview to GA
Copilot & AI Licensing

GAWork IQ API generally available, billing through Copilot Credits

Work IQ API GA. Custom agents and third-party AI platforms can ground on Microsoft 365 data with security and governance enforced at the API layer. Billing flows through Copilot Credits, meaning end-user use of grounded agents incurs charges back to the tenant. Important to surface to finance before makers start scaling third-party agents on top of Microsoft 365 content.

Action: align Copilot Credits monitoring with the makers' agent deployment plan; set a usage alert threshold in commerce.

Throughout
Jun
Copilot wave
Copilot & AI User-facing

Rolling outMicrosoft 365 Copilot app redesign

A streamlined, chat-centred experience with a simplified prompt and response layout and a refreshed navigation model. Visible to nearly all Copilot users in June. Update internal training screenshots and any embedded video walkthroughs the L&D team relies on.

Copilot & AI User-facing

GAAgentic capabilities in Word, Excel and PowerPoint

Copilot can plan, execute and refine multi-step work in-app: drafting a document end-to-end, running an analytical workflow across an Excel model, building a deck from a brief. Significant change-management impact on end-user training and on how the L&D and IT teams think about Copilot adoption metrics.

Copilot & AI User-facing

Rolling outCopilot Notebooks UI refresh with Teams meeting grounding

Notebooks now bring chats, output creations and references into a single UI, with the OneNote-side experience kept in sync. Notebooks can also ground on individual Teams meetings: transcripts, notes, chats and shared content as a single knowledge source per meeting. Useful for project reviews and incident retrospectives.

Copilot & AI Licensing

Rolling outCopilot Notebooks expanding to Copilot Chat tier

Notebooks is no longer Microsoft 365 Copilot licence-only. It is rolling out to broader Copilot Chat users in June. Watch for licensing-tier confusion among end users who may not realise the same Notebook can present a different feature set depending on the viewer's licence. A short FAQ in the internal Copilot hub avoids a wave of helpdesk tickets.

Throughout
Jun
Agent 365 wave
Copilot & AI Security

PreviewAgent 365 context mapping in Defender + Intune runtime blocking

New Agent 365 capabilities enter public preview in June. Defender surfaces asset and identity context maps per agent; Intune applies policy-based controls plus runtime blocking and alerts for OpenClaw, with the Shadow AI page in the Microsoft 365 admin centre exposing unmanaged agents touching tenant data. This is the month admins start seeing the full control plane Microsoft has been describing since May GA.

Action: open the Shadow AI page in the M365 admin centre and walk through the agent register. Record gaps in ownership / posture before scaling enforcement.

Copilot & AI Admin action

PreviewAgent 365 registry sync with AWS Bedrock and Google Cloud

Cross-platform agent observability. Admins can connect the Agent 365 registry to AWS Bedrock and Google Cloud connections to discover, inventory and (soon) lifecycle-manage agents across clouds. Relevant for organisations running AI workloads outside Azure and wanting a single agent register.

Endpoints & Intune Admin action

PreviewWindows 365 for Agents (US only)

A new class of Cloud PCs purpose-built for agentic workloads, managed in Intune, with the same identity, security and management controls used for employee Cloud PCs. Available only in the United States during preview. Worth a closer look for organisations piloting Agent 365 with a regulated data-residency workload.

Throughout
Jun
Collaboration
Collaboration User-facing

GAViva Engage events experience

Events in Viva Engage now supports conversation before, during and after an event with publish-once cross-surface engagement spanning SharePoint, Teams and Engage. Useful for all-hands and large announcements where the discussion thread is as important as the live moment.

Collaboration Admin action

Rolling outViva Engage admin modernisation: sensitivity labels + new email domain

Viva Engage admin gets sensitivity-label support, a new Engage email domain, improved admin workflows and stronger governance options. Useful for tenants running a Purview information-protection programme that previously had a documented Engage gap. Mail-flow teams need the new domain on the radar for transport-rule design and SPF / DMARC alignment.

Collaboration Security

Rolling outTeams External Domains Anomalies Report

A new admin report surfaces unusual or risky external interactions: spikes, new domains, abnormal engagement patterns across Teams external communications. Pairs well with Defender for Office 365's Teams ZAP and admin domain blocking. Worth wiring into the monthly Teams admin review.

Collaboration Admin action

Rolling outTeams: Microsoft 365 Certified App management at tenant level

Admins can now allow only Microsoft 365 Certified SaaS apps through org-wide settings, providing a vetted middle path between "everything allowed" and explicit allowlists. Useful when the SaaS shadow IT footprint is large enough that an explicit allowlist is impractical but everything-on is not acceptable.

Collaboration Admin action

Default changeTeams Copilot / Facilitator transcription behaviour: default policy changes

Teams Copilot / Facilitator no longer automatically starts transcription where the default policy moves from EnabledWithTranscript to Enabled. This is not the same as a global removal of Teams recording or transcription. It affects the Copilot / Facilitator transcription-start behaviour and should be reviewed by tenants that rely on automatic transcription for eDiscovery, Communication Compliance, meeting summaries or internal meeting guidance.

Action: review Teams meeting policies, Copilot / Facilitator guidance, eDiscovery assumptions and Communication Compliance workflows that depend on automatic transcription.

Throughout
Jun
Security & Purview
Security & Compliance Admin action

GASentinel Data Lake tier ingestion for Defender XDR Advanced Hunting tables

Direct ingestion of specific Defender XDR Advanced Hunting tables into the Sentinel data lake without analytics-tier ingestion. Designed for long-retention, cost-effective storage and retrospective hunts at scale. SOC budget owners should re-look at the data-tiering plan now that the data lake takes more of the XDR surface natively.

Security & Compliance Security

Operational reminderDefender for Office 365 Plan 1: validate Teams ZAP + admin quarantine workflow

Teams ZAP and admin management of quarantined Teams messages are now important baseline checks for Defender for Office 365 Plan 1 tenants. Although rollout and default enablement started earlier in 2026, June is a good point to validate that the operational workflow is actually working: quarantine review, Teams blocked domains, admin actions and user communications. A real upgrade for SMB tenants where P2 was previously out of reach.

Security & Compliance Admin action

GAPurview Data Security Investigations: audit-search-driven content collection

Inside DSI, audit-log-driven content collection is GA: query by time, activities, users and keywords, and DSI pulls the associated content into the investigation. Reduces time-to-evidence for insider-risk and incident-response teams. Where available and licensed, useful as a complement to Activity Explorer in DLP validation runbooks.

Security & Compliance Security

Rolling outPurview DLP for Microsoft 365 Copilot: web-search controls worldwide

Purview DLP for Copilot and Copilot Chat now extends to web searches containing sensitive data, with real-time controls. Preview landed in March; worldwide rollout in June. Worth a fresh look at the DLP policies that govern Copilot prompts and groundings, especially in tenants with regulated SITs in scope.

Security & Compliance Admin action

GAPurview DLP devices dashboard: 30-minute sync confirmation

The Devices dashboard now confirms DLP policies are synced to devices within 30 minutes of application. Always-on diagnostics is GA on macOS in addition to Windows. Useful for SOC and DLP teams who previously had to wait longer or rely on Advanced Hunting to confirm a policy had landed.

Throughout
Jun
Endpoints & Intune
Endpoints & Intune Admin action

GAIntune Linux support: Ubuntu 26.04 LTS in, Ubuntu 22.04 on the runway, RHEL to revalidate

Ubuntu 26.04 LTS is now supported in Intune for Linux. Ubuntu 22.04 LTS support is on the runway for retirement in August 2026, and RHEL 8 support should be validated against the current Microsoft Learn supported-distributions list before setting migration deadlines. The transition is not automatic; affected devices need an in-place upgrade or replacement before their distro support window closes.

Action: pull a Linux-by-distro Intune report; validate each distribution against the current Microsoft Learn support matrix; schedule Ubuntu 22.04 → 24.04 / 26.04 and any applicable RHEL migrations before the support window closes.

You are here
17 June 2026
Beyond this point, the items below haven't happened yet. They are the deadlines, defaults and Preview to GA transitions admins should be preparing for in the next two to six weeks. The next issue (early July) will report on the Sentinel cutover and the second half of June.
Impact Admin action Security User-facing Licensing Watch only
End Jun
Preview to GA
Collaboration User-facing

GA expectedSharePoint home site updates: Resources + Announcements web parts, News filmstrip

A refresh to the home site experience brings a Resources web part, an Announcements web part and new filmstrip layout options for News. Targeted Release was early May; GA expected by end of June. Tenants that use a home site as the intranet landing page should test custom home site web parts, SPFx extensions and any branding scripts in a test tenant before the rollout reaches production.

Endpoints & Intune Admin action

Warning rolls outIntune iOS MAM SDK warning for versions earlier than 20.8.0

From late June, users opening iOS apps built with Intune MAM SDK earlier than 20.8.0 see a warning to update for continued compatibility. ISVs of internal line-of-business iOS apps must be checked before the warning hits end users. Wholesale removal of older-SDK apps is on the runway after the warning period.

Action: confirm internal LOB iOS app SDK versions; engage ISVs whose apps are below the threshold to ship a refreshed build.

30 Jun
Retirement
Identity & Access Admin action

Read-only 30 JunConditional Access "Require approved client app" control

From 30 June, the Require approved client app control becomes read-only: no new policies, no edits. Existing policies continue to work, but migration to app protection policies is the documented path forward. Final deadline. No further extension signalled.

Before 30 June: filter the CA tenant for any policy with "approvedApplication" in grants alone, patch each one, validate in report-only, then re-enable enforcement.

1 Jul
Auto-redirect
Security & Compliance Admin action

Default changeSentinel users in the Azure portal auto-redirect to the Defender portal

From 1 July, Sentinel users in the Azure portal are automatically redirected to the Defender portal. All new Sentinel environments must be created in the Defender portal. The full Azure portal UI retires 31 March 2027, but day-to-day operations move next month. This is the single biggest SecOps operational change of the quarter.

Before 1 July: update SOC runbooks, screenshots and links; revalidate RBAC patterns under the Defender portal model; check SOAR endpoints and automation that target the Azure portal Sentinel surface.

6 Jul
Enforcement
Identity & Access Security

Default changeCA credential registration enforcement expands to Windows Hello for Business + macOS Platform SSO

From 6 July, CA policies scoped to the Register security information user action are evaluated during credential registration for Windows Hello for Business and macOS Platform SSO. Important for tenants enforcing trusted-location or compliant-device requirements at registration. Test in a pilot ring before the date if registration-time policies are restrictive.

Action: validate the credential-registration CA policy against WHfB and macOS Platform SSO sign-in flows in a pilot group before 6 July.

Throughout
Jul
Retirement + Watch
Endpoints & Intune Admin action

Validate supportLinux support matrix: validate RHEL and Ubuntu migration deadlines

Intune's supported Linux distribution list is changing, with Ubuntu 26.04 LTS now supported and older distributions needing validation against the current Microsoft Learn support matrix. Any RHEL 8 or Ubuntu 22.04 estate should be reviewed before July / August planning windows so unsupported distributions do not remain in the managed fleet unnoticed.

Security & Compliance Watch only

Preview expansionAI playbook generator in Sentinel / Defender XDR

A preview expansion for the AI playbook generator is signalled for July. The pattern: describe the response you want in natural language, get a SOAR playbook draft grounded on connected data. Worth keeping an eye on the Sentinel and XDR blogs for the next milestone if the SOC is sizing AI assistance into its 2026/2027 plan.

Editorial note: monthly update trackers are time-sensitive. Rollout dates, GA status, licensing terms and regional availability can change after publication. Treat this issue as an admin planning guide and validate production decisions against Microsoft Learn, Message Center, Roadmap and Product Terms.

Direct sources for the critical items are listed first, followed by pillar-level overview sources. Verify each link is still live before making policy changes for your tenant. Microsoft sometimes adjusts rollout schedules after publication.

Direct sources for critical items

ItemDirect source
Sentinel auto-redirect to Defender portal (1 Jul)Sentinel Blog, transition timeline
CA All-resources enforcement with exclusions — rollout from 13 May / June windowEntra Blog, CA enforcement change
CA "Require approved client app" read-only (30 Jun)Microsoft Learn, Migrate approved client app to APP
CA credential registration enforcement WHfB + macOS (6 Jul)Entra Blog, security updates to do now
Sentinel Repositories REST API retirement (15 Jun)Microsoft Learn, Sentinel what's new
Microsoft 365 E7 + Agent 365 GA (1 May, billing in Jun)Microsoft 365 Blog, E7 + Agent 365 GA
Agent 365 expansions (Defender + Intune + AWS / GCP)Microsoft Security Blog, Agent 365 expansions
Windows 11 KB5094126 (9 Jun)Microsoft Support, KB5094126
Microsoft 365 Copilot redesign + agentic Word/Excel/PPTM365 Blog, Copilot redesign
Copilot Notebooks UI refresh + Teams meeting groundingCopilot Blog, Notebooks June 2026
Power Platform ACP GA + connector inventoryPower Platform Blog, June 2026
Sentinel Data Lake tier ingestion GASentinel Blog, data lake tier ingestion GA
Intune iOS MAM SDK warning (late Jun) + Linux distro supportMicrosoft Learn, Intune what's new

Pillar overviews for other items

PillarPrimary source
Identity & Access (Entra, CA, PIM)Microsoft Entra Blog, June 2026
Security & Compliance (Defender XDR)Microsoft Learn, Defender XDR what's new
Defender for Office 365Microsoft Learn, Defender for Office 365 what's new
Microsoft Purview (DLP, DSI, IRM)Microsoft Learn, Purview what's new
Microsoft SentinelMicrosoft Learn, Sentinel what's new
Endpoints & IntuneMicrosoft Learn, Intune what's new
Collaboration (Teams, SharePoint, Viva)Viva Engage Blog, June 2026 + Teams admin release notes
Copilot & AI (Microsoft 365 Copilot, Agent 365, Copilot Studio, Security Copilot)Microsoft Learn, Copilot release notes
Microsoft 365 admin centre / Commerce / Partner CenterPartner Center, June 2026 announcements
Monthly Update Tracker
Microsoft 365 changes, monthly.

A recap of what shipped, what is coming and what admins should act on. New issue every first week of the month.

Next
Next

Microsoft 365: May 2026 Recap and What to Watch in June