A detailed look at what’s new across the hybrid data center and Microsoft Cloud ecosystem. From Cisco’s Unified Edge and VMware licensing shifts to Microsoft Copilot, Sentinel, and Power Platform advancements, each update highlights critical release timelines, admin implications, and security considerations so IT leaders can plan strategically and stay compliant.
What’s the Buzz in November? It’s eGroup Enabling Technologies!
We’re proud to share that eGroup has been named to the 2025 Inc. Power Partner Awards list, recognizing top B2B organizations that go above and beyond to help their clients succeed.
This honor reflects our commitment to providing an exceptional customer experience, lasting partnerships, and expertise that helps organizations achieve proven results; like helping Pearson enhance identity management with Microsoft Entra, supporting Verdantas in driving secure AI innovation across their global workforce, and strengthening cybersecurity for Genesis Healthcare with our ThreatDefender MXDR service.
Together with our clients, we’re building smarter, more secure, and more connected organizations. Here’s what just the clients above are saying about eGroup:
“Bring eGroup in earlier… The partnership helped us accelerate, learn, and ultimately own the solution.”
— Tim Brantner, Senior Director of Identity and Access Management at Pearson
“I’ve worked with many Microsoft partners, eGroup definitely stood out in terms of your dedication to customer success. From day one, you came in and said, ‘We are here for your success.’ The approach that you have taken is not a vendor-customer relationship, but a customer-partner relationship. I truly appreciate that.”
— Sujan Turlapaty, Chief Digital Information Officer at Verdantas
“As far as I’m concerned, people at eGroup are members of our IT department in every way imaginable.”
— Marcellus Moore, CTO at Genesis Healthcare

What’s New in the Hybrid Data Center?
Cisco
–Unified Edge, Next-Gen Wireless & Security Advisories
Cisco expanded edge compute for AI workloads and modernized campus/branch networking while issuing urgent security guidance for ASA/FTD customers.
–Cisco issued a security advisory on Nov 5, warning of a new attack variant targeting devices running ASA and Cisco Secure FTD with previously disclosed vulnerabilities (CVE-2025-20362 and CVE-2025-20333). These attacks can cause denial-of-service (DoS) by forcing unpatched devices into reboot loops.
View full Cisco update
Unified Edge for AI Inferencing: New modular platform unifies compute, networking, storage, and security to run low-latency AI at the edge for manufacturing/retail/healthcare. Plan for on-prem GPU/DPUs and secure data locality to reduce cloud egress costs.
Catalyst CW9800L Controller (Release): Branch/small-campus wireless controller for hybrid cloud topologies; prioritize upgrade windows to align with existing Catalyst/Meraki policies and HA pairs.
Secure Enterprise Network Architecture (Preview): Unifying control layer with automation/analytics across Catalyst + Meraki; Global Overview in Meraki Dashboard enters beta November 2025. Review role-based access and API governance before enabling.
UCS X9508/X210c M8 (3rd Gen): The third-generation UCS X9508 chassis and X210c M8 compute nodes support a range of workloads, from enterprise virtualization to AI and machine learning. Advancements include fabric-first architecture with unified 100G+ connectivity, next-generation Intel Xeon 6th Gen processors, and support for NVIDIA A100 and A30 accelerators.
Nutanix
–AI Networking and License Simplification
Nutanix advanced its AI-ready infrastructure and simplified data-protection licensing, enhancing both performance and security for enterprise workloads.
Don’t miss our ongoing Disaster Recovery blog series, as we dive in deeper to Nutanix DR: Part 3, Part 4, Part 5, and Part 6. Join next week’s The Future of Disaster Recovery with Nutanix webinar to be part of the discussion in real-time!
–Data-at-Rest Encryption (DARE) in NCI Pro Licenses: Beginning with AOS 7.3, software-based encryption is included in Pro tiers without requiring an additional add-on license, simplifying compliance and key management for regulated environments.
View full Nutanix update
NVIDIA DPU and SuperNIC Integration: Nutanix Flow now supports NVIDIA BlueField DPUs and ConnectX SuperNICs to deliver high-throughput, low-latency, and secure networking tailored to AI applications.
Nutanix Database Service (NDB) 2.9: The update adds native Oracle Data Guard integration, providing true disaster-recovery capabilities for Oracle databases across Single Instance, HA, and RAC configurations—all within a single NDB console.
Virtualization Cost Considerations: Nutanix highlighted that the total cost of virtualization extends well beyond hypervisor licensing to include power, cooling, subscriptions, and operational overhead, underscoring the value of holistic cost modeling.
Cohesity
–Version 7.3 Long-Term Support (LTS): Cohesity dropped a new Long-Term Support release with 7.3, with stronger ransomware defense with tamper-proof snapshots and machine learning-based anomaly detection, and seamless integration with Amazon S3 Glacier and Azure Archive, enabling cost-efficient long-term data retention. And they’ve improved instant VM recovery speed for VMware/Nutanix and added dedicated network isolation for Kubernetes backup traffic.
View full Cohesity update
Partnership with Semperis: A new collaboration combines Cohesity’s immutable backup and rapid recovery with Semperis’ identity-threat detection and attack-path analysis, improving resilience for Active Directory and Entra ID environments. The joint solution combines Cohesity’s secure, clean backup and rapid recovery capabilities with Semperis’ identity threat detection and attack-path analysis, helping organizations protect and quickly restore their core identity services.
Identity Resilience and FortKnox Enhancements
Cohesity strengthened ransomware protection, identity recovery, and backup isolation through product updates and new integrations.
FortKnox Self-Managed Option: Organizations can now host isolated, immutable data copies within their own environment. Combined with Alta Recovery Vault and expanded DataProtect / NetBackup support, this model offers greater deployment flexibility and control.
Oracle Cyber Resilience: Cohesity now provides enhanced recovery workflows for Oracle environments, streamlining backup operations and accelerating post-incident restoration. Learn how they are integrating with Oracle tools, simplifies operations, and provides immutable backups and fast threat detection.
Rubrik
–BMC Firmware Vulnerability (Supermicro Clusters): Customers using r6000 or r7000 hardware should disable IPMI or restrict access to mitigate a newly discovered BMC firmware exposure in Supermicro components.
View full Rubrik update
Security Cloud and Hardware Guidance
Rubrik issued firmware advisories and expanded its Security Cloud capabilities for more granular retention and AI-driven data operations.
Annapurna AI Interface: The new AI-driven query experience in Rubrik Security Cloud allows secure, natural-language interaction with backup metadata through chatbots and APIs, improving visibility and operational insight.
Cloud Native Protection—Static Retention: The feature adds granular control to prevent accidental deletion of snapshots and meet regulatory data-retention requirements.
CDM Maintenance Update: Rubrik advises customers to upgrade to the latest maintenance releases within their current CDM version to ensure access to the newest features and enhancements. Specifically, organizations running CDM 9.4 should move to version 9.4.1, those on CDM 9.3 should update to 9.3.3-p2, and customers on CDM 9.2 are encouraged to upgrade to 9.2.3-p8.
Citrix
–License Activation Service (LAS): Beginning April 15, 2026, all deployments must use the new cloud-based LAS system. File-based legacy licenses will cease functioning, requiring organizations to migrate their entitlements ahead of the deadline to avoid user disruption. Deployments using the legacy file-based licensing mechanisms will have end-user impacts. For more details, please read this post.
Zerto
–Version 10.8 Cyber Recovery Improvements
Zerto’s latest release integrates advanced detection workflows and strengthens defensive configurations.
View full Zerto update
CrowdStrike Integration (v10.8): When CrowdStrike identifies suspicious activity, Zerto automatically tags recovery checkpoints for clean rollbacks, reducing investigation time and limiting exposure.
ICMP Echo Default Change (10.7.20+): Echo requests are now disabled by default to reduce reconnaissance risk, though administrators can temporarily enable them through the CLI when diagnostics require it.
VMware
-Bring-Your-Own VCF Subscriptions: As of November 1st, Broadcom has altered its licensing policies across all hyperscaler platforms to require customers to “bring your own” portable subscription for VMware Cloud Foundation (VCF). This means customers must purchase portable VCF subscriptions directly from Broadcom to use with cloud services in the future, including Azure VMware Solution.

What’s New in Microsoft Cloud?
Azure
–Azure Storage Discovery, which supports the analysis of storage utilization and security on Azure Blob storage and Azure Data Lake, is now generally available. Azure Storage Recovery captures and analyzes metrics and trends related to capacity consumption and transactions, and provides reports on data protection and security configurations.
Azure: Storage Migration, Discovery, and VM Lifecycle
Azure broadened storage migration scenarios and clarified virtual-machine retirement timelines while improving disaster-recovery performance.
- Azure Storage Mover (NFS 3 & 4 to Azure Files 4.1): Migration coverage now includes NFSv3 and NFSv4 sources, expanding on SMB and AWS S3 support for hybrid content transfers.
- VM Series Retirement (Effective Nov 15, 2028): The F, Fs, Fsv2, Lsv2, G, Gs, Av2, Amv2, and B VM families will be retired. Organizations should plan workload migrations to newer SKUs well in advance of this cutoff.
- Azure Site Recovery for Ultra Disks: ASR now supports the highest-performance disk tier, offering sub-millisecond latency for critical workloads that require near-instant failover.
Microsoft 365 Copilot
-Through December, Microsoft 365 Copilot will introduce real-time voice interactions in Podcast, enabling users to engage in dynamic, conversational audio experiences by asking questions during document-based podcasts.
Microsoft 365 Copilot: Agents, Security, and Experience Updates
Microsoft Copilot continues to expand agent capabilities, administrative controls, and multimodal experiences.
- Natural-Language App and Flow Creation: Users can now generate apps and workflows conversationally, while IT admins retain DLP and environmental governance controls.
- Tenant-Wide Agent Pinning and Cataloging: Pinned agents can appear across the organization, increasing discoverability while adhering to scoped-content permissions.
- Windows Copilot App Enhancements: Copilot for Windows now supports exporting prompts into Word, Excel, and PDF documents, helping knowledge workers transform insights into formatted outputs.
- Authoritative SharePoint Sites for Copilot Search: Admins may designate up to 100 sites as trusted content sources to improve Copilot Search relevance.
- Explore Pane (Mid-Nov 2025): A guided side-panel experience will help users learn Copilot features in context across Create, Search, and Notebooks.
- Scoped Chat Sources (Mid-Dec 2025): Licensed users will soon select specific repositories for Copilot Chat, enabling finer control over data exposure.
- MCP-Based Agents (Mid-Nov Rollout): Developers can publish managed Copilot agents via the Agent Store and Admin Center, introducing standardized oversight and approval workflows.
- Persistent AI Disclaimer (Late Nov): A new admin option allows bolded disclaimers and custom URLs linking to organizational AI-use policies.
- Copilot Notebooks Redesign (Mid-Jan 2026): The landing experience will emphasize AI-generated summaries and contextual insights.
- Admin Approval Flows for Built-In Agents (Late Nov–Mid-Dec): Administrators gain centralized visibility and approval control over Microsoft-developed agents.
- Copilot Studio Threat Detection (GA Dec 10): External security systems can now monitor agent runtime activity for compliance and risk analysis.
Defender XDR
-The latest updates for Microsoft Defender XDR include the ability to use tasks in the Microsoft Defender portal to break investigations into actionable steps and assign across operations teams. Tenants that have onboarded Microsoft Sentinel can also automate tasks between Sentinel and the Defender portal.
Defender XDR: Integrated Tasking and Contextual Visibility
Defender XDR updates focus on operational coordination and richer incident context.
- Task Assignments in Defender Portal: Investigations can be divided into discrete tasks assignable across SOC teams, aligning workflows with structured incident-response playbooks.
- Sentinel Automation Integration: Sentinel-connected tenants can automate bidirectional tasks between the two portals, improving cross-tool remediation.
- Sensitivity-Label Filtering (GA): Analysts can now filter incidents and alerts by document sensitivity labels, adding data-protection context to triage decisions.
Sentinel
-Microsoft rolled out a lot of upcoming changes to Sentinel aimed at reorienting the platform for better AI utilization while also reducing the cost for organizations to consume.
Sentinel: Data Lake, Unified Portal, and Cost Controls
Sentinel’s new architecture and billing model prepare security teams for the AI era.
- Sentinel Data Lake (Preview): Enables low-cost, large-scale data retention with open-format storage, unified querying, and ML notebooks. The new architecture supports long-term telemetry analysis and advanced hunting. This FAQ covers everything from architecture to billing for the new data-lake feature. It is especially useful for security teams planning long-term retention, advanced hunting, and Lake-tier strategy.
- Defender Portal Unification (Before July 2026): Sentinel workspaces can now move into the Defender portal for a seamless SIEM + XDR experience and streamlined analyst workflows.
- Capacity Unit Commitments: Pre-purchasing analytics units provides predictable budgeting and volume-based discounts.
- Agentic Security Approach: Sentinel and Defender now enable AI agents that leverage graph context and vectorized data to strengthen proactive threat detection. Our own article at eGroup Enabling Technologies highlights how the “agentic era” changes SOC operations, and how Sentinel’s new capabilities let you build and manage custom agents for detection, response, and automation.
Entra ID
-Entra ID now supports single sign-on for macOS devices, simplifying authentication for Apple users.
Entra ID: AI-Driven Identity Governance and Simplified Access
New intelligence and access capabilities improve identity security and usability.
- Security Copilot in Entra: Adds AI-generated insights to detect misconfigurations and recommend policy optimizations for identity governance.
- Continuous Policy Analysis Agent: Evaluates policies against emerging threats to maintain streamlined, effective access controls.
- QR + PIN Authentication for Frontline Workers: Offers a simplified sign-in method to reduce friction for shift-based employees.
- Entra Connect Upgrade Deadline (Sep 2026): Version 2.5.79.0 or later is required to ensure secure directory synchronization with Active Directory.
Exchange
–CISA / NSA Security Guidance: A joint publication provides best practices for protecting on-premises Exchange servers, including network isolation, patch discipline, and EDR deployment.
Intune
-By December 2, update firewall configurations to include new Azure Front Door IP addresses for Microsoft Intune. Add the service tag “AzureFrontDoor.MicrosoftSecurity” to allow outbound traffic on port 443. Do not remove existing Intune endpoints to ensure uninterrupted device and app management.
Intune: Privilege Elevation, Policy Updates, and Network Changes
- Endpoint Privilege Management Update: The new “Elevate as current user” option runs installers in the user context with MFA verification, improving compatibility and auditability.
- Windows 25H2 Policy Controls: Administrators can immediately manage new AI and Start menu settings within preview builds.
Loop
-IT admins can now manage Loop files like other SharePoint files, with support for version history, audit logs, and compliance workflows.
Loop: Expanded Copilot Integration and Compliance Support
- Copilot Pages Integration: Loop pages now serve as collaborative canvases for Copilot-generated content, bridging AI insights and team editing.
- SharePoint-Backed Governance: Loop files inherit SharePoint versioning, audit logs, and compliance workflows.
- Cross-App and External Sharing: Components now work across Teams, Outlook, OneNote, and Whiteboard, with admin controls for external collaboration.
Outlook (New)
Outlook (New): Mobile Copilot for Meetings
- Meeting Preparation Feature (Late Nov): Android and iOS users with Copilot licenses gain chat-based meeting summaries and insights generated securely under existing policy boundaries.
Planner
Planner: Integration and Compliance Enhancements
- Project Manager Agent Integration: Tasks can be created directly from Teams meetings and chats, ensuring better accountability and visibility for follow-ups.
- Information Barrier (IB) Support: Extends compliance controls to prevent collaboration between restricted user segments.
Power Platform
-Data agents created in Copilot Studio can now be managed using modern software development practices like CI/CD, ALM flow, and Git integration.
Power Platform: AI-Assisted Design and Governance Modernization
Microsoft continues to evolve the Power Platform to make app creation and automation more accessible while aligning with enterprise-grade governance, security, and lifecycle management standards.
- AI-Powered Solution Builder (Power Apps): The Power Platform’s new AI designer allows anyone—from citizen developers to solution architects—to describe a business challenge in natural language and receive an automatically generated app or workflow structure. The system iteratively refines requirements through conversation, producing early-stage prototypes and requirement documents for development teams. Available now at make.powerapps.com, this experience helps organizations shorten the gap between ideation and delivery while maintaining alignment with DLP policies and environment governance.
- Data Agent Lifecycle Management (Copilot Studio): Data agents created in Copilot Studio can now be version-controlled through modern DevOps practices, including CI/CD pipelines, ALM flows, and Git integration. Teams can track, test, and deploy agent updates within structured approval workflows, ensuring reliability across environments and compliance with audit requirements. These changes enable “chat-with-your-data” capabilities under robust governance—bridging AI-powered data access with traditional software development rigor.
- InfoPath End-of-Life (July 14, 2026): With support for InfoPath forms and associated workflows ending soon, organizations should begin migrating legacy applications to Power Apps and Power Automate. Microsoft recommends using the Microsoft 365 Assessment Tool to inventory all existing InfoPath dependencies and plan replacements. Beyond replication, organizations can modernize their workflows with Copilot Studio’s generative AI capabilities, transforming static form logic into intelligent, agent-driven experiences that improve user engagement and operational efficiency.
Purview
-Purview DLP adds inline file upload protection in Edge for Business to prevent data leaks to unmanaged GenAI apps. Admins can enforce policies by file size, type, and sensitivity on Intune-managed Windows devices. Public preview starts mid-November; GA begins early December.
Purview: Data Lifecycle and AI DLP Expansion
- Priority Cleanup Policies (Early 2026): Admins will be able to simulate and enforce early deletion of OneDrive and SharePoint content, with dual-admin approvals to satisfy compliance requirements.
- Edge for Business DLP (Preview Mid-Nov, GA Early Dec): Adds inline file-upload protection against unmanaged GenAI apps, enforcing controls by file type, size, and sensitivity.
- Copilot Security Controls (Preview Nov, GA Jan): Introduces DLP creation, oversharing monitoring, and policy visibility directly in the Microsoft Admin Center.
SharePoint
SharePoint: AI-Powered FAQ Enhancements (Late 2025)
- Intelligent FAQ Management: New Copilot-driven features will help authors update and validate FAQs automatically while grounding answers in existing SharePoint Pages.
Teams
-Microsoft Teams will allow users to chat with anyone via email, even non-Teams users, who join as guests. Available to small and medium businesses, this feature rolls out from November 2025 and is enabled by default.
Teams Chat — Guest Access Expansion
- Chat via Email (Nov 2025): Users can now chat with external participants who join as guests using email, broadening collaboration options for small and mid-sized organizations.
Teams Meetings — Room AI Facilitator and Enhanced AV Control
Microsoft is enhancing Teams meeting environments with new AI-powered assistance, adaptive video layouts, and improved accessibility and control for large-scale events.
- Facilitator Agent for Teams Rooms on Android: The Facilitator agent introduces real-time AI support inside meeting chats, automatically generating notes, follow-up items, and time-management prompts during discussions. This feature streamlines post-meeting actions and ensures consistent documentation across teams. IT admins should validate privacy disclosures and ensure room devices are running the latest firmware to enable these capabilities securely.
- Dynamic Video Tile Resizing: Teams Rooms on Android now automatically adjust video tile sizes based on the number of in-room participants. When one person is present, the tile matches a remote attendee’s size, while multiple participants trigger an expanded layout up to four times larger. This delivers a more natural viewing experience for remote participants and improves meeting equity across hybrid teams.
- Live Caption Translation (40 Languages): Live captions can now translate spoken language into any of 40 supported languages for in-room attendees. This accessibility enhancement benefits global and multilingual organizations, though admins should confirm bandwidth and CPU capacity for optimal performance during large meetings.
- Town Hall and Webinar View Controls: Large-event organizers can now switch between presenter and attendee front-of-room views without impacting remote participants. This gives moderators greater flexibility in managing visual flow and audience engagement during live events. Admins should review meeting-room device policies and update event management runbooks to incorporate these new controls.
Teams Phone — CCaaS and Dynamics 365 Integration
- Unified Telephony Workflows: New extensibility connects Teams Phone with CCaaS and Dynamics 365 Contact Center, allowing shared reporting and call control data across platforms.
Teams Admin Center — Collaboration Modes and Security Filtering
- External Collaboration Modes (Mid-Nov Preview → GA Feb): Three new options—Open, Controlled, and Custom—simplify configuration and policy auditing.
- Trust-Based App Filters (Oct 23): Admins can now apply SOC 2, ISO 27001, HIPAA, and GDPR criteria to accelerate app reviews and surface potential risks.
Windows
–Windows 10 End of Free Updates (Oct 14, 2025): October 14, 2025, was the final free security update for Windows 10 in its standard servicing channel. Organizations still running Windows 10 must prepare for either migration to Windows 11 or enrollment in the Extended Security Updates (ESU) program (available for up to three additional years) to maintain security posture. Windows 10 devices accessing Windows 365 Enterprise Cloud PCs and Windows 365 Frontline (Dedicated) Cloud PCs are automatically entitled to Windows 10 Extended Security Updates (ESU).
