Deadlines
Every dated obligation the weekly issues have carried — retirements, cutovers, KEV due dates. Repeats across weeks are folded into one entry, kept in the wording of the issue that reported it last. The countdown runs against your clock, not the build.
Still ahead · 8
-
1 Sep 2026 in 1 day
Passkeys become the default authentication method in Microsoft Entra ID. From this date, users enabled for SMS or voice are automatically enabled and nudged to register a passkey at multifactor sign-in, and native SMS and voice authentication is then discontinued on 1 Feb 2027, after which affected users must register a passkey to sign in with no opt-out. Identify who still relies on telephony MFA, enable synced or device-bound passkeys, and run registration campaigns now rather than at cutover; monitor for bypass attempts during the transition.
-
7 Sep 2026 in 7 days
Self-service password reset stops accepting authentication methods that were never explicitly registered. Directory-sourced phone numbers and email addresses will no longer work for SSPR — only registered methods. Drive users through the July registration campaign so they are not locked out of reset when this flips.
-
14 Sep 2026 in 14 days
the containerized data connector agent for the Microsoft Sentinel solution for SAP applications is permanently disabled and stops sending SAP logs to Sentinel. Migrate to the SAP agentless data connector before then; the migration runs side by side with no coverage gap, and existing analytics rules, workbooks, hunting queries and playbooks keep working. If you miss the date, everything built on that SAP data silently stops returning results.
-
30 Sep 2026 in 30 days
Entra Custom controls retire (end of life May 2027). Third-party MFA integrations wired through Custom controls must move to External MFA to stay supported. Existing configs keep working through the transition, but start migration planning now.
-
26 Oct 2026 in 56 days
Microsoft Entra ID is retiring custom CSS positioning properties in company-branded sign-in pages. As of 21 July 2026, tenants not already using these properties can no longer configure them, and on 26 October 2026 the positioning properties are retired globally — logos, images, and text stay visible but revert to their default placement, with no migration path, so any tenant still relying on them must remove them before the cutover. Microsoft frames this as an anti-phishing measure: removing arbitrary layout control shrinks the room to build convincing look-alike sign-in pages. Inventory your branded sign-in configurations now, confirm whether any use positioning CSS, and plan the visual change ahead of enforcement rather than discovering it when the page shifts.
-
27 Oct 2026 in 57 days
Microsoft Defender for Cloud stops enabling Foundational CSPM by default on new Azure subscriptions and moves it to an opt-in model. Existing Azure subscriptions keep their current configuration and AWS and GCP environments are unaffected, so this is a question of what a newly created subscription looks like on day one rather than a change to what you already have. Foundational CSPM stays free and can be turned on at any time, but a subscription created after the cutover starts with no posture management until someone enables it, which is exactly the gap that gets missed when a project team spins up a subscription outside the usual process. If your landing-zone automation or subscription-vending pipeline assumes posture coverage arrives for free, add an explicit enablement step before late October.
-
31 Mar 2027 in 212 days
Managing Microsoft Sentinel in the Azure portal is sunset (extended from 1 Jul 2026). Begin planning the move to the Defender portal now; new capabilities ship there only.
-
16 Aug 2027 in 350 days
the classic Defender for SQL APIs for Vulnerability Assessment and Advanced Threat Protection retire. Microsoft posted the retirement notice on 17 August 2026, giving twelve months of notice. If you have scripts, runbooks or automation that call those APIs to read SQL vulnerability assessment results or manage Advanced Threat Protection settings, migrate them to the supported configuration model before the date; anything left behind stops returning results rather than failing loudly.
No fixed date · 2
-
Jun 2026
Secure Boot 2023 certificates expire. Microsoft Secure Score now surfaces the "Ensure devices are updated to Secure Boot 2023 certificates and boot manager" recommendation so you can find endpoints that haven't transitioned; work the list before the expiration or affected devices lose Secure Boot trust.
-
Summer 2026
The ASIM `ProcessEvent` parsers deprecate the legacy `targetusername` parameter of `_Im_ProcessCreate`; the documented name is now `targetusername_has`. Both are accepted today, so update analytic rules and hunting queries that call the process-create parser before the old parameter is removed.
Passed · 17
-
25 Aug 2026 6 days ago
CISA added CVE-2026-68820, the actively exploited Windows WinSock driver elevation of privilege fixed on 11 August, to the Known Exploited Vulnerabilities catalogue on 11 August with a remediation due date of 25 August under BOD 26-04. Federal agencies are bound by that date; for everyone else it is a reasonable ceiling on how long an exploited local SYSTEM escalation should sit unpatched.
-
1 Aug 2026 30 days ago
The Microsoft Azure Network Adapter (MANA) rollout reaches MANA-eligible Intel v1–v4 VM sizes in the public cloud, the earliest date those VMs can be placed on MANA-capable hardware. Network Virtual Appliances — including third-party firewalls and other security appliances — depend directly on the underlying network hardware and drivers, so an NVA whose OS or vendor build doesn't support MANA can see degraded or interrupted traffic. If yours isn't confirmed MANA-compatible, apply and enable the LegacyVMNVA Azure Policy tag before this date to hold those VMs off MANA hardware (honored until 31 May 2027); the MANA-eligible Cobalt 100 and Intel v5 sizes already passed their 26 May 2026 date.
-
31 Jul 2026 31 days ago
Legacy grouped recommendations are removed from the Azure portal. They now show as "Set for deprecation"; the individual recommendations that replace them are GA. Re-point any automation, exemptions, or workbooks that key off the old grouped recommendation IDs before the cutoff.
-
14 Jul 2026 48 days ago
July's Patch Tuesday is the largest on record, fixing roughly 570 vulnerabilities including 59 critical and three zero-days. Two are already being exploited: CVE-2026-56155, an Active Directory Federation Services (AD FS) elevation-of-privilege flaw, and CVE-2026-56164, a missing-authentication elevation-of-privilege bug in SharePoint Server; the third, CVE-2026-50661, is a publicly disclosed BitLocker bypass requiring physical access. Prioritize the AD FS and SharePoint fixes on identity-federation and internet-facing systems now, and hunt for exploitation on those hosts rather than waiting for the full-fleet rollout.
-
6 Jul 2026 56 days ago
Conditional Access enforcement for the *Register security information* action extends to Windows Hello for Business provisioning and macOS Platform SSO registration, closing a long-standing gap where those flows were unenforced. The same week, an SSPR registration campaign begins. Test any CA policies scoped to registration flows in report-only mode before the rollout so device setup does not start failing for users who cannot satisfy the policy.
-
1 Jul 2026 61 days ago
Unified RBAC migration groundwork before the Defender-portal cutover (heads-up). Legacy Sentinel Azure roles do not carry into the Defender portal, so plan URBAC migration to avoid permission gaps; Workspace Manager deprecation pushes MSSPs toward CI/CD via GitHub or Azure DevOps.
-
1 Jul 2026 61 days ago
The `AIAgentsInfo` advanced hunting table is retired and replaced by the unified `AgentsInfo` table (public preview), which covers agent inventory and governance across Copilot Studio, Microsoft Foundry, M365 Copilot, third-party, and endpoint-discovered agents. Any saved hunts, custom detections, or workbooks still referencing `AIAgentsInfo` stop returning results after this date — repoint them to `AgentsInfo`.
-
1 Jul 2026 61 days ago
Sentinel standardizes the Account Name entity: the `Name` field now consistently holds only the UPN prefix (the part before `@`), with the full UPN and suffix moved to dedicated fields. Analytics rules, automation rules, playbooks, and hunting queries that compare `Name` against a full UPN silently stop matching. Rebuild the full value from `Name` + `UPNSuffix`, or use `coalesce()` to set a precedence order.
-
15 Jun 2026 77 days ago
Older Sentinel repositories (content-as-code) Source Control API versions become unsupported after today. CI/CD tooling that creates or manages repo connections must move to API version 2025-09-01, 2025-06-01, or 2025-07-01-preview; existing connections keep operating. If your team deploys analytics rules and playbooks from GitHub or Azure DevOps, confirm the pipeline is on a supported API version.
-
15 Jun 2026 77 days ago
Conditional Access enforcement for *All resources* policies that carry resource exclusions begins. Only tenants with such a policy are affected; if you own custom apps that request only OIDC or a limited set of directory scopes, confirm they can handle CA challenges (MFA / device compliance) before this date.
-
1 Jun 2026 91 days ago
Microsoft Entra ID begins blocking Entra Connect Sync and Cloud Sync from *hard-matching* a newly synced on-premises Active Directory user onto an existing cloud-managed Entra user that holds an Entra role. It closes a Source-of-Authority takeover path where an on-prem foothold manipulates AD attributes to seize a privileged cloud account. Soft match, and hard match for non-role-holding users, are unaffected. If you run hybrid sync, confirm no privileged cloud accounts still depend on hard-match behavior before today, or legitimate syncs will start throwing hard-match errors.
-
1 Jun 2026 91 days ago
Legacy Microsoft Sentinel repositories (content-as-code) API versions retire in June 2026, and Source Control create/manage calls on the old versions will start failing. If you drive repo connections through the REST API or pipelines, move to API version 2025-09-01, 2025-06-01, or 2025-07-01-preview before this date. Existing repository connections keep operating; only API calls on the retired versions break.
-
13 Apr 2026 140 days ago
Defender for Cloud deprecates the preview grouped container vulnerability recommendations (the "Containers running in Azure/AWS/GCP should have vulnerability findings resolved" set and their registry equivalents), replacing them with per-finding individual recommendations. If any governance rules, exemptions, workbooks, or automation query the old grouped recommendation keys, migrate them to the individual-recommendation format and `securityresources` KQL now, before the keys disappear.
-
1 Apr 2026 152 days ago
Microsoft Sentinel begins charging Security Compute Units (SCUs) for the entity analyzer tool in the Sentinel MCP data-exploration collection. If your team picked up entity analyzer for out-of-the-box URL and identity risk assessments after its RSAC-week GA, those runs now draw down SCUs; review MCP usage so agent-driven queries don't surprise your Sentinel bill.
-
1 Apr 2026 152 days ago
In Azure Government (Fairfax), Defender for Cloud announced an enhanced agent for the Defender for SQL Server on machines plan that uses existing SQL infrastructure instead of the Azure Monitor Agent (AMA). If you enabled this plan before April 2026, update the plan configuration; protection-status verification for your SQL instances is expected to start around May 2026.
-
16 Feb 2026 196 days ago
CISA's deadline for U.S. federal (FCEB) agencies to patch CVE-2026-21509, an actively exploited Microsoft Office security-feature-bypass zero-day that Microsoft fixed in an out-of-band update on 26 January. It isn't a legal mandate for private orgs, but it's a useful forcing function: the flaw affects Microsoft 365 Apps and Office 2016 / 2019 / LTSC 2021 / LTSC 2024 and sits on CISA's Known Exploited Vulnerabilities list. Prioritize pushing the out-of-band Office update across your estate.
-
13 Jan 2026 230 days ago
January Patch Tuesday shipped fixes for roughly 113 CVEs (trackers count 112–114 depending on how third-party items are tallied), including CVE-2026-20805, a Desktop Window Manager information-disclosure flaw Microsoft reports as exploited in the wild, plus two other publicly disclosed zero-days. The DWM bug scores only CVSS 5.5, but info-leak flaws like it are typically chained to defeat ASLR and turn an unreliable memory-corruption exploit into a repeatable one, so don't deprioritise it on score alone. Deploy the January cumulative update across your Windows fleet and use Defender Vulnerability Management to confirm which devices are still exposed.