Microsoft 365 June 2026 Roundup: What Shipped, What's Next
What shipped in Microsoft 365 in the first half of June 2026, plus the deadlines, defaults and Preview to GA transitions admins should be preparing for in late June and July. Scan the timeline. Bookmark for the next issue.
- Microsoft Sentinel is moving into the Defender portal on 1 July. Automatic redirect for users still on the Azure portal, new Sentinel environments only in the Defender portal. The full Azure portal UI retires 31 March 2027, but day-to-day SecOps moves next month. Update runbooks, RBAC and SOAR endpoints in the next two weeks.
- Three Conditional Access enforcement changes converge across May, June and July. Improved enforcement for All-resources policies with resource exclusions started rolling out from 13 May and continues through the June window; "Require approved client app" goes read-only on 30 June; credential registration evaluation expands to Windows Hello for Business and macOS Platform SSO on 6 July. Verify report-only logs ahead of each step.
- Agent 365 expands across Defender, Intune and Windows 365. Public previews this month for context mapping in Defender, runtime blocking for OpenClaw via Intune, registry sync with AWS Bedrock and Google Cloud, and Windows 365 for Agents (US preview only). Agent governance is now a tenant-wide conversation, not just a Copilot Studio one.
- Microsoft 365 Copilot got a visible redesign plus agentic capabilities in Word, Excel and PowerPoint. End users will notice. Notebooks expand to Copilot Chat tier and can now ground on individual Teams meetings (transcripts, notes, chats, shared content). Update change-management material now.
- Work IQ API is GA and billing through Copilot Credits. Custom agents and third-party AI platforms can now ground on Microsoft 365 data with governance enforced at the API layer. Charges flow back to the tenant. Finance needs the heads-up before makers scale.
Validate per tenantAgent 365 licensing and prerequisites need tenant-by-tenant validation
Agent 365 is available through Microsoft 365 E7 and may also be available through standalone or add-on licensing depending on tenant eligibility, programme and commercial terms. Because packaging and prerequisites are evolving, do not assume coverage from a lower SKU or from a previous quote. Validate the current terms with Microsoft Product Terms, the customer's CSP / partner and the tenant's actual eligibility before designing the rollout.
Action: confirm the current Agent 365 quote line, prerequisites and eligible base licences with the CSP / partner before including Agent 365 in a project scope or budget.
Billing rollingMicrosoft 365 E7 commerce cycles reflect the 1 May GA
Microsoft 365 E7 went GA on 1 May and bundles Microsoft 365 E5-level productivity / security capabilities with Microsoft 365 Copilot, Agent 365 and advanced identity / security capabilities. June is one of the first practical commercial planning windows after the 1 May GA for customers comparing their existing E5 + Copilot + Agent 365 + Entra Suite stack against Microsoft 365 E7. If E7 is on the renewal radar, this is the right moment to map the existing stack against E7 list before the next renewal cycle locks in.
PreviewPower Platform inventory shows connector footprint per resource
A new connectors column rolls out across canvas apps, model-driven apps, cloud flows, agent flows and agents, letting admins see at a glance which connectors each resource calls. Public preview from 2 June. Pairs well with the Advanced Connector Policies GA later in the month for governance teams responsible for the maker estate.
KB5094126Windows 11 June cumulative update: desktop.ini hardening
The June Patch Tuesday update introduces security hardening for the processing of desktop.ini in content downloaded from remote locations. The side effect known so far: some users see missing custom folder icons or localised folder names. Test against your standard images before broad deployment, especially in environments that rely on branded folder icons or localised file shares.
Action: confirm pilot ring sees no regression in branded / localised folder rendering before broad ring opens. Link KB to the change ticket.
GAPower Platform Advanced Connector Policies (ACP) generally available
ACP is GA, giving admins finer control over which connectors and which connector operations can run in which environments. Material for tenants with a sizeable maker community across multiple environments; pairs with the new connectors-column inventory preview from 2 June. Worth a fresh look at existing DLP connector policies before rolling out the more granular ACP rules.
Action: inventory current connector DLP groupings; identify where ACP gives meaningful enforcement value over what DLP groups already cover.
Rolling outConditional Access improved enforcement for All-resources policies with exclusions
Microsoft Entra ID started rolling out improved enforcement for Conditional Access policies targeting All resources with resource exclusions from 13 May 2026, with rollout continuing through the June window. Tenants with policies that relied on the older exclusion behaviour may see previously masked blocks, MFA prompts or session controls.
Action: filter the Conditional Access tenant for any All-resources policy with exclusions, review sign-in logs / report-only impact, and confirm sign-ins to previously excluded scopes still behave as expected.
Retires 15 JunMicrosoft Sentinel Repositories REST API: older versions retired
Source Control actions using older Sentinel Repositories REST API versions stop working from 15 June. CI / CD pipelines and infrastructure-as-code wiring that pushes Sentinel content packs through Git must be on the current API surface. The break tends to surface during the next pipeline run rather than instantly.
Action: grep the IaC repo and Git-backed Sentinel content pipelines for old API versions; pin to current ones in the deployment definitions.
GAWork IQ API generally available, billing through Copilot Credits
Work IQ API GA. Custom agents and third-party AI platforms can ground on Microsoft 365 data with security and governance enforced at the API layer. Billing flows through Copilot Credits, meaning end-user use of grounded agents incurs charges back to the tenant. Important to surface to finance before makers start scaling third-party agents on top of Microsoft 365 content.
Action: align Copilot Credits monitoring with the makers' agent deployment plan; set a usage alert threshold in commerce.
Jun
Rolling outMicrosoft 365 Copilot app redesign
A streamlined, chat-centred experience with a simplified prompt and response layout and a refreshed navigation model. Visible to nearly all Copilot users in June. Update internal training screenshots and any embedded video walkthroughs the L&D team relies on.
GAAgentic capabilities in Word, Excel and PowerPoint
Copilot can plan, execute and refine multi-step work in-app: drafting a document end-to-end, running an analytical workflow across an Excel model, building a deck from a brief. Significant change-management impact on end-user training and on how the L&D and IT teams think about Copilot adoption metrics.
Rolling outCopilot Notebooks UI refresh with Teams meeting grounding
Notebooks now bring chats, output creations and references into a single UI, with the OneNote-side experience kept in sync. Notebooks can also ground on individual Teams meetings: transcripts, notes, chats and shared content as a single knowledge source per meeting. Useful for project reviews and incident retrospectives.
Rolling outCopilot Notebooks expanding to Copilot Chat tier
Notebooks is no longer Microsoft 365 Copilot licence-only. It is rolling out to broader Copilot Chat users in June. Watch for licensing-tier confusion among end users who may not realise the same Notebook can present a different feature set depending on the viewer's licence. A short FAQ in the internal Copilot hub avoids a wave of helpdesk tickets.
Jun
PreviewAgent 365 context mapping in Defender + Intune runtime blocking
New Agent 365 capabilities enter public preview in June. Defender surfaces asset and identity context maps per agent; Intune applies policy-based controls plus runtime blocking and alerts for OpenClaw, with the Shadow AI page in the Microsoft 365 admin centre exposing unmanaged agents touching tenant data. This is the month admins start seeing the full control plane Microsoft has been describing since May GA.
Action: open the Shadow AI page in the M365 admin centre and walk through the agent register. Record gaps in ownership / posture before scaling enforcement.
PreviewAgent 365 registry sync with AWS Bedrock and Google Cloud
Cross-platform agent observability. Admins can connect the Agent 365 registry to AWS Bedrock and Google Cloud connections to discover, inventory and (soon) lifecycle-manage agents across clouds. Relevant for organisations running AI workloads outside Azure and wanting a single agent register.
PreviewWindows 365 for Agents (US only)
A new class of Cloud PCs purpose-built for agentic workloads, managed in Intune, with the same identity, security and management controls used for employee Cloud PCs. Available only in the United States during preview. Worth a closer look for organisations piloting Agent 365 with a regulated data-residency workload.
Jun
GAViva Engage events experience
Events in Viva Engage now supports conversation before, during and after an event with publish-once cross-surface engagement spanning SharePoint, Teams and Engage. Useful for all-hands and large announcements where the discussion thread is as important as the live moment.
Rolling outViva Engage admin modernisation: sensitivity labels + new email domain
Viva Engage admin gets sensitivity-label support, a new Engage email domain, improved admin workflows and stronger governance options. Useful for tenants running a Purview information-protection programme that previously had a documented Engage gap. Mail-flow teams need the new domain on the radar for transport-rule design and SPF / DMARC alignment.
Rolling outTeams External Domains Anomalies Report
A new admin report surfaces unusual or risky external interactions: spikes, new domains, abnormal engagement patterns across Teams external communications. Pairs well with Defender for Office 365's Teams ZAP and admin domain blocking. Worth wiring into the monthly Teams admin review.
Rolling outTeams: Microsoft 365 Certified App management at tenant level
Admins can now allow only Microsoft 365 Certified SaaS apps through org-wide settings, providing a vetted middle path between "everything allowed" and explicit allowlists. Useful when the SaaS shadow IT footprint is large enough that an explicit allowlist is impractical but everything-on is not acceptable.
Default changeTeams Copilot / Facilitator transcription behaviour: default policy changes
Teams Copilot / Facilitator no longer automatically starts transcription where the default policy moves from EnabledWithTranscript to Enabled. This is not the same as a global removal of Teams recording or transcription. It affects the Copilot / Facilitator transcription-start behaviour and should be reviewed by tenants that rely on automatic transcription for eDiscovery, Communication Compliance, meeting summaries or internal meeting guidance.
Action: review Teams meeting policies, Copilot / Facilitator guidance, eDiscovery assumptions and Communication Compliance workflows that depend on automatic transcription.
Jun
GASentinel Data Lake tier ingestion for Defender XDR Advanced Hunting tables
Direct ingestion of specific Defender XDR Advanced Hunting tables into the Sentinel data lake without analytics-tier ingestion. Designed for long-retention, cost-effective storage and retrospective hunts at scale. SOC budget owners should re-look at the data-tiering plan now that the data lake takes more of the XDR surface natively.
Operational reminderDefender for Office 365 Plan 1: validate Teams ZAP + admin quarantine workflow
Teams ZAP and admin management of quarantined Teams messages are now important baseline checks for Defender for Office 365 Plan 1 tenants. Although rollout and default enablement started earlier in 2026, June is a good point to validate that the operational workflow is actually working: quarantine review, Teams blocked domains, admin actions and user communications. A real upgrade for SMB tenants where P2 was previously out of reach.
GAPurview Data Security Investigations: audit-search-driven content collection
Inside DSI, audit-log-driven content collection is GA: query by time, activities, users and keywords, and DSI pulls the associated content into the investigation. Reduces time-to-evidence for insider-risk and incident-response teams. Where available and licensed, useful as a complement to Activity Explorer in DLP validation runbooks.
Rolling outPurview DLP for Microsoft 365 Copilot: web-search controls worldwide
Purview DLP for Copilot and Copilot Chat now extends to web searches containing sensitive data, with real-time controls. Preview landed in March; worldwide rollout in June. Worth a fresh look at the DLP policies that govern Copilot prompts and groundings, especially in tenants with regulated SITs in scope.
GAPurview DLP devices dashboard: 30-minute sync confirmation
The Devices dashboard now confirms DLP policies are synced to devices within 30 minutes of application. Always-on diagnostics is GA on macOS in addition to Windows. Useful for SOC and DLP teams who previously had to wait longer or rely on Advanced Hunting to confirm a policy had landed.
Jun
GAIntune Linux support: Ubuntu 26.04 LTS in, Ubuntu 22.04 on the runway, RHEL to revalidate
Ubuntu 26.04 LTS is now supported in Intune for Linux. Ubuntu 22.04 LTS support is on the runway for retirement in August 2026, and RHEL 8 support should be validated against the current Microsoft Learn supported-distributions list before setting migration deadlines. The transition is not automatic; affected devices need an in-place upgrade or replacement before their distro support window closes.
Action: pull a Linux-by-distro Intune report; validate each distribution against the current Microsoft Learn support matrix; schedule Ubuntu 22.04 → 24.04 / 26.04 and any applicable RHEL migrations before the support window closes.
GA expectedSharePoint home site updates: Resources + Announcements web parts, News filmstrip
A refresh to the home site experience brings a Resources web part, an Announcements web part and new filmstrip layout options for News. Targeted Release was early May; GA expected by end of June. Tenants that use a home site as the intranet landing page should test custom home site web parts, SPFx extensions and any branding scripts in a test tenant before the rollout reaches production.
Warning rolls outIntune iOS MAM SDK warning for versions earlier than 20.8.0
From late June, users opening iOS apps built with Intune MAM SDK earlier than 20.8.0 see a warning to update for continued compatibility. ISVs of internal line-of-business iOS apps must be checked before the warning hits end users. Wholesale removal of older-SDK apps is on the runway after the warning period.
Action: confirm internal LOB iOS app SDK versions; engage ISVs whose apps are below the threshold to ship a refreshed build.
Read-only 30 JunConditional Access "Require approved client app" control
From 30 June, the Require approved client app control becomes read-only: no new policies, no edits. Existing policies continue to work, but migration to app protection policies is the documented path forward. Final deadline. No further extension signalled.
Before 30 June: filter the CA tenant for any policy with "approvedApplication" in grants alone, patch each one, validate in report-only, then re-enable enforcement.
Default changeSentinel users in the Azure portal auto-redirect to the Defender portal
From 1 July, Sentinel users in the Azure portal are automatically redirected to the Defender portal. All new Sentinel environments must be created in the Defender portal. The full Azure portal UI retires 31 March 2027, but day-to-day operations move next month. This is the single biggest SecOps operational change of the quarter.
Before 1 July: update SOC runbooks, screenshots and links; revalidate RBAC patterns under the Defender portal model; check SOAR endpoints and automation that target the Azure portal Sentinel surface.
Default changeCA credential registration enforcement expands to Windows Hello for Business + macOS Platform SSO
From 6 July, CA policies scoped to the Register security information user action are evaluated during credential registration for Windows Hello for Business and macOS Platform SSO. Important for tenants enforcing trusted-location or compliant-device requirements at registration. Test in a pilot ring before the date if registration-time policies are restrictive.
Action: validate the credential-registration CA policy against WHfB and macOS Platform SSO sign-in flows in a pilot group before 6 July.
Jul
Validate supportLinux support matrix: validate RHEL and Ubuntu migration deadlines
Intune's supported Linux distribution list is changing, with Ubuntu 26.04 LTS now supported and older distributions needing validation against the current Microsoft Learn support matrix. Any RHEL 8 or Ubuntu 22.04 estate should be reviewed before July / August planning windows so unsupported distributions do not remain in the managed fleet unnoticed.
Preview expansionAI playbook generator in Sentinel / Defender XDR
A preview expansion for the AI playbook generator is signalled for July. The pattern: describe the response you want in natural language, get a SOAR playbook draft grounded on connected data. Worth keeping an eye on the Sentinel and XDR blogs for the next milestone if the SOC is sizing AI assistance into its 2026/2027 plan.
Editorial note: monthly update trackers are time-sensitive. Rollout dates, GA status, licensing terms and regional availability can change after publication. Treat this issue as an admin planning guide and validate production decisions against Microsoft Learn, Message Center, Roadmap and Product Terms.
Direct sources for the critical items are listed first, followed by pillar-level overview sources. Verify each link is still live before making policy changes for your tenant. Microsoft sometimes adjusts rollout schedules after publication.
Direct sources for critical items
| Item | Direct source |
|---|---|
| Sentinel auto-redirect to Defender portal (1 Jul) | Sentinel Blog, transition timeline |
| CA All-resources enforcement with exclusions — rollout from 13 May / June window | Entra Blog, CA enforcement change |
| CA "Require approved client app" read-only (30 Jun) | Microsoft Learn, Migrate approved client app to APP |
| CA credential registration enforcement WHfB + macOS (6 Jul) | Entra Blog, security updates to do now |
| Sentinel Repositories REST API retirement (15 Jun) | Microsoft Learn, Sentinel what's new |
| Microsoft 365 E7 + Agent 365 GA (1 May, billing in Jun) | Microsoft 365 Blog, E7 + Agent 365 GA |
| Agent 365 expansions (Defender + Intune + AWS / GCP) | Microsoft Security Blog, Agent 365 expansions |
| Windows 11 KB5094126 (9 Jun) | Microsoft Support, KB5094126 |
| Microsoft 365 Copilot redesign + agentic Word/Excel/PPT | M365 Blog, Copilot redesign |
| Copilot Notebooks UI refresh + Teams meeting grounding | Copilot Blog, Notebooks June 2026 |
| Power Platform ACP GA + connector inventory | Power Platform Blog, June 2026 |
| Sentinel Data Lake tier ingestion GA | Sentinel Blog, data lake tier ingestion GA |
| Intune iOS MAM SDK warning (late Jun) + Linux distro support | Microsoft Learn, Intune what's new |
Pillar overviews for other items
| Pillar | Primary source |
|---|---|
| Identity & Access (Entra, CA, PIM) | Microsoft Entra Blog, June 2026 |
| Security & Compliance (Defender XDR) | Microsoft Learn, Defender XDR what's new |
| Defender for Office 365 | Microsoft Learn, Defender for Office 365 what's new |
| Microsoft Purview (DLP, DSI, IRM) | Microsoft Learn, Purview what's new |
| Microsoft Sentinel | Microsoft Learn, Sentinel what's new |
| Endpoints & Intune | Microsoft Learn, Intune what's new |
| Collaboration (Teams, SharePoint, Viva) | Viva Engage Blog, June 2026 + Teams admin release notes |
| Copilot & AI (Microsoft 365 Copilot, Agent 365, Copilot Studio, Security Copilot) | Microsoft Learn, Copilot release notes |
| Microsoft 365 admin centre / Commerce / Partner Center | Partner Center, June 2026 announcements |
A recap of what shipped, what is coming and what admins should act on. New issue every first week of the month.