๐ข Just shippedGA 2026-09-29
Organizations that authenticate Microsoft 365 users through an external identity provider can now extend browser-based passkeys, security keys and eligible single sign-on sessions to Outlook, Teams, OneDrive, Word, Excel, PowerPoint and Microsoft To Do on Android, iOS and managed macOS. The external provider's sign-in step opens in the system browser instead of an embedded web view, then returns to the Microsoft identity broker. Applies to tenants federated through WS-Fed or SAML 2.0.
Why it matters: Removes the embedded web view limitation that blocked sign-in where an identity provider required passkeys, so a phishing-resistant rollout can cover the M365 mobile apps.
techcommunity.microsoft.com
๐ข Just shippedDeprecation 2026-09-29
The visual investigation view linking impacted data, users and alert activity is being removed: configuration was already withdrawn in early September 2026, new onboarding ended September 24, and retirement runs from early December to full removal on December 8, 2026. Investigators move to Activity explorer, Content explorer and User activity. Applies to Worldwide, GCC, GCC High and DoD.
Why it matters: Insider-risk investigation playbooks that screenshot or reference the graph need rewriting against the explorer views before December 8.
m365admin.handsontek.net
Deprecation 2026-09-29
Retirement of both classic Data Security Posture Management experiences starts November 30, 2026 and completes by December 31, 2026, with capabilities folded into a single current DSPM experience covering traditional data sources plus AI applications and agents. Applies to Worldwide, GCC, GCC High and DoD.
Why it matters: Any DSPM for AI reporting built on the classic portal view stops working at the end of the year, so Copilot data-risk reporting has to be rebuilt on the unified experience.
m365admin.handsontek.net
๐ก Coming soonPlanned Oct 2026
A Content Security Policy on login.microsoftonline.com will allow only trusted Microsoft-hosted scripts during authentication, blocking externally injected code as part of the Secure Future Initiative. General availability runs worldwide from mid-October to late October 2026. Entra External ID tenants are not affected. Restated from MC1191924.
Why it matters: Browser extensions, monitoring or branding tools that inject script into the sign-in page will break, so inventory them before mid-October.
m365admin.handsontek.net