Top Microsoft 365 Message Center & Roadmap Updates - August 2026
Last month's Microsoft 365 Message Center items were heavy on identity and access changes, most notably the retirement of SMS and voice MFA and the shift to passkeys as the default. There were also meaningful updates to the governance of external communication, including tighter controls on federated Teams chats and a new cross-tenant message recall capability in Exchange Online.
Below are five Message Center items we think warrant particular attention, along with some of the more impactful Roadmap updates on their way.
However, this is just a starting point. Every month, Microsoft publishes dozens of changes across the Microsoft 365 estate and not all of them make it into a blog. The items here represent a small selection of what's out there. If you want to be confident you're not missing the changes that matter to your organisation, you need more than a monthly roundup.
Sign up to get the ChangePilot monthly bulletin, curated Microsoft 365 Message Center and Roadmap insights delivered straight to your inbox.
Prefer to watch? Here's the full video walkthrough of this month's top 10 updates:
Top 5 Microsoft 365 Message Center Items - August 2026
Staying ahead of these updates helps IT, security, governance, and digital workplace teams reduce risk and support a smooth experience for end users as Microsoft 365 evergreen change continues to accelerate.
MC1426371 – Passkeys by Default and Retirement of SMS/Voice MFA (Entra)
Microsoft is making passkeys the default authentication method in Entra, while simultaneouslyretiring SMS and voice call MFA options. This is one of the most significant identity changes in recent memory as it affects every user in your tenant and the retirement of legacy MFA methods is irreversible once enforced.
What's changing:
- Passkeys (FIDO2/device-bound) will become the default sign-in method for supported users
- SMS and voice call MFA options are being retired, so these will no longer be available as authentication factors
- Users still relying on SMS or voice MFA will need to be migrated to alternative methods before enforcement
Deployment details:
- Rolling out from July 2026; check your Message Center for tenant-specific timelines
Recommended actions:
- Audit your current MFA method distribution; identify how many users rely on SMS or voice MFA
- Begin user migration to supported methods (Microsoft Authenticator, passkeys, OATH tokens) as a priority
- Communicate the change proactively to end users, especially those less familiar with app-based authentication
- Update your identity and access management runbooks and helpdesk scripts
- Review Conditional Access policies to ensure they align with the new default authentication landscape
MC1423106 – Introducing Cross-Tenant Message Recall in Exchange Online (Exchange)
Microsoft is introducing the ability to recall messages sent to recipients in external organisations via Exchange Online, a capability that was previously limited to within the same tenant.
This significantly expands the scope of message recall, but also introduces new governance considerations around what can and cannot be recalled across organisational boundaries.
Microsoft's official announcement confirms that control sits with the receiving tenant, which must explicitly opt in before any cross-tenant recall can succeed.
What's changing:
- Users can now attempt to recall emails sent to recipients in other Microsoft 365 tenants
- Recall success depends on whether the recipient's organisation and mail client support the feature
- This expands message recall beyond the internal tenant boundary for the first time
Deployment details:
- Rolling out July 2026
Recommended actions:
- Brief your legal, compliance, and records management teams: cross-tenant recall has implications for document retention and evidence preservation
- Review your email governance and acceptable use policies to determine whether guidance on message recall needs updating
- Educate users on the limitations of cross-tenant recall - it is not guaranteed and depends on recipient-side support
- Consider whether any regulatory obligations (e.g. eDiscovery holds) could be affected by users attempting cross-tenant recalls
MC1423114 – Stricter External Access Controls for Federated Chats (Teams)
Microsoft is introducing more granular and restrictive controls for federated chats in Teams (the conversations that take place between users in different Microsoft 365 organisations). Administrators will have greater ability to define who can initiate and participate in federated chats, helping organisations manage cross-boundary collaboration risk.
What's changing:
- New admin controls allow more precise scoping of which external domains or users can initiate federated chats
- Existing federated chat configurations may be affected depending on how the new controls are applied
- Designed to give organisations stronger governance over unsolicited or uncontrolled external messaging
Deployment details:
- Rolling out July-September 2026
Recommended actions:
- Review your current Teams external access and federation settings before this change lands
- Assess whether your existing configuration needs to be updated to align with the new controls
- Identify any business-critical external collaboration flows that use federated chat and ensure they will not be disrupted
- Communicate changes to teams that regularly collaborate with external partners via Teams chat
- Update your collaboration governance documentation to reflect the new control options
MC1417993 – File Policies in Microsoft Defender for Cloud Apps Are Retiring (Defender)
Microsoft is retiring File Policies in Defender for Cloud Apps, a capability used by many organisations to monitor and control file activity across connected cloud applications. This is a significant change for teams who rely on Defender for Cloud Apps as part of their data security and compliance posture.
What's changing:
- File Policies in Defender for Cloud Apps will be retired and will no longer function after the enforcement date
- Organisations using File Policies for data governance, DLP, or compliance monitoring will need to migrate to supported alternatives
- Microsoft is directing customers toward Microsoft Purview as the recommended replacement capability
Deployment details:
- Retirement timeline live - check your Message Center for your tenant-specific deadline
Recommended actions:
- Audit your existing Defender for Cloud Apps File Policies to understand what is currently in scope and what business purpose each policy serves
- Map each retiring policy to an equivalent capability in Microsoft Purview using Microsoft's official migration guide — File Policies retire on January 6, 2027
- Engage your security and compliance teams to agree on a migration plan before the retirement deadline
- Test replacement policies in a non-production environment before migrating live controls
- Update your security operations runbooks and any documentation that references File Policies
MC1409304 – Facilitator Proactively Detects and Resolves Knowledge Gaps in Meetings (Teams + Copilot)
Microsoft Facilitator (the AI meeting assistant in Teams) will now detect when meeting participants appear to lack context or understanding of topics being discussed, and surface relevant information or explanations in real time.
What's changing:
- Facilitator identifies knowledge gaps during live meetings based on conversation signals
- Relevant context, definitions, or background information is surfaced to participants who may need it
- Designed to improve meeting equity and reduce the need for follow-up clarification
Deployment details:
- Rolling out July
Recommended actions:
- Review your Microsoft Copilot and Facilitator admin settings to understand whether this capability is enabled in your tenant
- Consider the implications for sensitive or confidential meetings — Facilitator's proactive suggestions are visible to participants
- Update user guidance on what Facilitator can do, so employees understand the new proactive behaviour
- Align with your AI governance policies to confirm this level of in-meeting AI assistance is acceptable in your organisatio
Top 5 Microsoft 365 Roadmap Items - August 2026
Here are the key Roadmap updates released in the last month. As Microsoft adjusts timelines, keep an eye on your tenant's rollout messages and update internal comms accordingly.
568075 – Microsoft Purview: Data Security for Non-Microsoft Connected Apps
Microsoft Purview is expanding its data loss prevention capabilities to cover non-Microsoft apps connected to your Microsoft 365 environment, closing a significant gap in data security coverage for organisations that use third-party SaaS tools alongside Microsoft 365.
Rolling out:
- September 2026
Recommended actions:
- Identify which non-Microsoft apps are connected to your Microsoft 365 environment and assess what data flows between them
- Review your existing Purview DLP policies to determine whether they need to be extended to cover newly supported apps
- Engage your data governance and compliance teams to prioritise which third-party app connections require policy coverage
- Update your data security documentation to reflect the expanded scope of Purview protection
567306 – Microsoft Teams: Enhanced Delegated Calling Restrictions
Microsoft is introducing enhanced controls for delegated calling in Teams Phone, giving administrators and users more precise options for restricting who can make or receive calls on behalf of another user.
Rolling out:
- August 2026
Recommended actions:
- Review your current delegated calling configurations and assess whether the new restriction options would improve governance or security
- Brief telephony admins and PAs or EAs who use delegation features; behaviour may change depending on how new restrictions are applied
- Update your Teams Phone governance documentation to reflect the new controls
567884 – Microsoft Teams: External Call Routing for DoD and GCC High
Microsoft is extending external call routing capabilities to Teams Phone deployments in DoD and GCC High environments, improving telephony parity for government cloud customers.
Rolling out:
- September 2026
Recommended actions:
- If your organisation operates in a GCC High or DoD environment, assess whether this capability is relevant to your telephony configuration
- Review your call routing policies and determine whether updates are needed to take advantage of the new routing options
- Engage your Microsoft partner or account team for guidance specific to your government cloud deployment
567304 – Microsoft Teams: Explicit Call Recording and Transcription Consent for GCC High and DoD
Microsoft is rolling out explicit consent prompts for call recording and transcription in Teams for GCC High and DoD environments — bringing government cloud deployments in line with commercial compliance requirements.
Rolling out:
- August 2026
Recommended actions:
- If your organisation operates in a GCC High or DoD environment, review your recording and transcription policies before this feature lands
- Update legal and compliance documentation to reflect the new explicit consent mechanism
- Brief your service desk and meeting hosts on the new consent prompts so they can handle user questions accurately
567468 – Microsoft Teams Rooms on Android: Modernised Gallery View
Microsoft is rolling out a modernised gallery view for Teams Rooms on Android, updating the meeting room display layout to improve how remote participants are shown during hybrid meetings.
Rolling out:
- August 2026
Recommended actions:
- If your organisation uses Teams Rooms on Android, assess whether any room configurations or AV setups need to be updated to accommodate the new layout
- Brief your AV and facilities teams on the change so they can support end users during the transition
- Consider whether any user guidance or room signage needs to be updated
Master Microsoft 365 Evergreen Change with ChangePilot
This month's selection tells a clear story: identity and access security is being fundamentally reset, and cross-boundary governance is tightening across both messaging and collaboration surfaces.
The retirement of SMS and voice MFA, stricter federated chat controls, and cross-tenant message recall all demand deliberate action. These are not passive rollouts that can be monitored and deferred. Organisations that haven't audited their MFA method mix or reviewed their external collaboration configurations are already behind.
Meanwhile, the retirement of Defender for Cloud Apps File Policies reinforces the broader migration toward Purview as Microsoft's unified compliance platform. This consolidation has significant implications for teams with established DLP and governance workflows.
The August Roadmap adds further depth to the calling and compliance story, with Purview expanding to non-Microsoft apps and Teams Phone governance controls becoming more granular. The pattern is clear: Microsoft is raising the floor on security and compliance capability and expecting organisations to keep pace.
To stay ahead of evergreen change, focus on:
- Reviewing updates regularly and assessing business impact
- Aligning rollout timing with organisational readiness
- Communicating major changes to stakeholders (especially security/compliance and the service desk)
- Using dashboards or tracking tools to maintain visibility and reduce "surprise" change
Sign up for the free monthly Bulletin — if you're not ready to commit, get the curated update delivered to your inbox each month.
Comments