Five security-related changes are landing across Microsoft Entra, Exchange Online, Microsoft Defender, and Teams between now and October 2026. Some turn on automatically; others require deliberate enablement, but all of them reward the organisations that review them before the deadlines arrive.
| MC ID | Change | Deadline | On by default? | Action required? |
| MC1423114 | Teams stricter external access controls | 31 July / 30 Sept 2026 | No | Yes - act before 31 July |
| MC1423106 | Exchange Online cross-tenant message recall | Mid-Aug 2026 | No | Yes - decide before mid-August which tenants to allow-list |
| MC1426371 | Entra passkeys default + SMS / voice MFA retirement | 1 Sept 2026 / 1 Feb 2027 | Auto-enables for affected users | Yes - plan before September |
| MC1437671 | Passwordless password change in My Sign-Ins | Late Oct 2026 | No | Optional - review strategy before October |
| MC1422060 | Defender prompt injection protection for email | GA Sept 2026 | Yes | No - review quarantine workflows |
Two new Teams PowerShell controls are arriving in July and September that close a long-standing gap in federated group chat governance.
External Access Restrictions: (31 July 2026)
Users whose External Access Policy has EnableFederationAccess set to False can no longer be added to external federated group chats and are automatically removed from existing active ones.
Mutual Federation (30 September 2026)
All participants in a federated chat must be able to federate with every other tenant in the chat. Those who don't meet the mutual federation requirement cannot join or be added.
Both controls are disabled by default, but enabling either one can result in users being removed from existing chats with no warning to those users unless you communicate first.
Action: If enabling either control, review your Allowed Domains list, identify users with EnableFederationAccess set to False, and brief stakeholders and helpdesk before switching them on.
From mid-August 2026, Exchange Online will support cross-tenant message recall. For the first time, a sender can attempt to recall a message delivered to a recipient in a different Microsoft 365 tenant, provided the receiving tenant has opted in and added the sending organisation to their allow list.
The feature is disabled by default. Receiving tenants control everything: whether to enable it at all, and which external organisations are permitted to recall messages.
Configuration is via Exchange Online PowerShell using the new Set-CrossTenantRecallConfiguration cmdlet.
This is a governance decision, not just a technical one. Enabling recall gives an external organisation an additional point of control over content that has already been delivered into your environment. For regulated sectors — legal, financial services, healthcare — there may be compliance implications around message retention, legal hold, and eDiscovery that require sign-off before enabling.
Action: Make a deliberate decision before mid-August. Identify partner organisations you would trust, assess compliance implications, and if enabling, prepare the PowerShell configuration and communicate the change to users and helpdesk.
Read the full breakdown of this item in detail in our blog.
From 1 September 2026
Passkeys will become the default authentication experience in Microsoft Entra.
Users currently enabled for Microsoft-provided SMS or voice MFA will have passkeys automatically enabled, and the Registration Campaign will be set to Microsoft-managed, prompting users to register a passkey at their next MFA sign-in (skippable).
From 1 February 2027
Microsoft-provided SMS and voice MFA will be retired entirely.
If your organisation still needs telephony MFA, you must configure a customer-managed telecom provider via the Microsoft Security Store, available from 30 October 2026. Microsoft recommends completing setup at least four weeks before the February retirement date.
A temporary opt-out is available between September 2026 and February 2027 to delay passkey enablement while you transition. Tenants that take no action and rely solely on Microsoft-provided telephony face sign-in disruption after 1 February 2027.
Action: Decide now whether you still need telephony MFA. If yes, plan the provider setup for November. If not, plan your passkey migration and communicate upcoming registration prompts to users and helpdesk.
Many organisations are adopting passkeys and passwordless authentication but still maintain passwords for legacy applications, on-premises services, or hybrid environments. The problem is, if a user doesn't know their current password, they have to use SSPR or contact the helpdesk.
From late October 2026, Microsoft Entra is introducing a passwordless password change experience in My Sign-Ins. Users with a strong passwordless credential i.e., a passkey, FIDO2 security key, or Windows Hello for Business, will be able to change their password without knowing the current one, and without triggering SSPR or a helpdesk call.
The feature is disabled by default and must be explicitly enabled by administrators. There is no per-user or per-group scoping; it is tenant-wide.
Action: Review your password management and passwordless authentication strategy before October. If enabling, brief helpdesk teams and update user guidance so they know the new self-service option exists.
Prompt injection is no longer just a theoretical AI risk. Attackers are embedding malicious instructions directly into emails — content designed to manipulate AI assistants like Copilot into leaking data, exposing system prompts, or exfiltrating information when the email is processed.
Microsoft Defender for Office 365 now detects and blocks this category of attack. Emails identified as prompt injection are classified as High Confidence Phish with a new detection label: Prompt Injection Protection, visible in quarantine and Threat Explorer. They are automatically quarantined before any AI-powered workflow, including Copilot email summarisation, can process them.
What you need to know:
Action: No enablement required. Brief your security and helpdesk teams on the new detection category and review quarantine workflows so legitimate emails aren't left unprocessed.
Across these five changes, it is clear that there is a pattern: Microsoft is giving administrators more controls over authentication, over AI-targeted threats, over what crosses tenant boundaries. Some of these changes arrive quietly and switch on by default; others require deliberate action before GA. Either way, they only deliver value if someone is paying attention and making decisions before the deadlines arrive.
The organisations that manage M365 change well aren't the ones reacting when a user asks why something stopped working. They're the ones that saw it coming in Message Center, routed it to the right decision-makers, and had a plan in place before GA.
If you want a reliable system for tracking what's in Message Center and what needs action, ChangePilot is built for exactly that.