What’s New in the Hybrid Data Center & Microsoft | April 2026

Hybrid Data Center Team

eGroup

April’s updates reflect a clear shift toward AI-driven operations, hybrid flexibility, and security-first architecture across both data center and cloud environments. Vendors are prioritizing automation, post-quantum readiness, and agentic AI governance while Microsoft continues embedding Copilot and security intelligence across its stack. The pace of change requires IT leaders to reassess architecture, identity, and operational models now.


Join Our Microsoft Virtual Roadshow (May 19–21, 2026)

Get a practical look at how organizations are modernizing cloud, security, productivity and AI across Microsoft platforms.

  • Day 1 – Azure + Security: Cloud strategy, application modernization, secure workspaces, and Defender for Cloud
  • Day 2 – Microsoft 365 + Security: Productivity, collaboration, identity protection, and governance across M365
  • Day 3 – Data + AI: Moving from AI pilots to scalable, governed solutions with Microsoft AI and Power Platform

Register for all three days or choose the sessions that fit your priorities.


What’s New in the Hybrid Data Center?

Cisco

Unified Fabric, AI-Aware Security, and Post-Quantum Readiness
Cisco continues to unify networking, security, and hybrid operations with a strong focus on AI-era demands and operational simplicity.

View full Cisco update
  • Unified Management with Hyperfabric
    Cisco introduced a Meraki-like dashboard for hybrid environments, enabling centralized management across on-prem and cloud. Hyperfabric will run natively on Nexus 9300 switches starting Q2 2026, allowing hardware reuse and flexible OS switching, reducing operational complexity and capital spend.
  • Meraki + Catalyst Hybrid Management Expansion
    C9350 Smart Switches now support onboarding to the Meraki Dashboard in Device Configuration mode, combining cloud simplicity with CLI-level control. This enables remote management flexibility while reducing the need for on-site intervention.
  • AI-Powered SASE Traffic Optimization
    Cisco SASE now includes AI traffic detection, intent-aware inspection, and unified SD-WAN/SSE policy enforcement. These capabilities identify not just traffic patterns but also intent, improving protection against emerging AI-driven threats.
  • IOS XE 26 Post-Quantum Cryptography
    Cisco introduced full-stack post-quantum cryptography across routing and switching platforms, including 8000 Series routers and C9000 switches. This aligns with global efforts to mitigate “harvest now, decrypt later” risks.
  • Cisco + Nutanix Enterprise Agreement Integration
    Nutanix Cloud Platform is now included in Cisco’s Enterprise Agreement, simplifying procurement and offering an alternative path for organizations reassessing VMware licensing strategies. More information can be found here.
  • Unified AI Infrastructure with Nutanix
    Joint integrations across Cisco Intersight and Nutanix Prism Central enable zero-touch provisioning, GPU-ready AI workloads, and unified control across hybrid environments.

Rubrik

Intelligent Recovery and AI Governance
Rubrik is focusing on operationalizing cyber resilience and bringing intelligence into both recovery and AI policy enforcement.

View full Rubrik update
  • Microsoft 365 Ransomware Recovery Prioritization
    Rubrik published a great read this month on a problem most organizations don’t think about until it’s too late. When ransomware affects a Microsoft 365 environment, the real challenge isn’t restore speed, but restoring the right things first. Microsoft’s API limits mean a full unstructured restore can take weeks.
  • Autonomous Business Recovery for M365
    Rubrik enables prioritized recovery of critical users and data dependencies across Teams, SharePoint, and Exchange. This addresses API limitations that make full restores impractical at scale.
  • SAGE Engine for AI Agent Governance
    Rubrik introduced semantic policy enforcement that understands intent rather than relying on keyword matching, enabling scalable governance of AI agents. Rubrik published a timely article on AI agent governance this month.
  • Clean Recovery Validation with Nutanix Integration
    Continuous snapshot scanning ensures organizations know their last clean recovery point before restoration begins, enabling parallel recovery workflows.
  • Rubrik and Nutanix Cyber Recovery Integration Enhancements
    Rubrik and Nutanix continue to enhance joint cyber recovery capabilities, with continuous snapshot scanning to identify clean restore points before an attack occurs. Combined with AHV and Flow, this enables isolated recovery and parallel security and IT workflows to speed response. This is a great read for any Nutanix customer thinking about cyber recovery

Cohesity

Expanded Cyber Resilience and Workload Coverage
Cohesity’s 7.4 release strengthens cyber vaulting, expands workload support, and enhances cloud protection capabilities.

View full Cohesity update
  • FortKnox Self-Managed Enhancements
    New features include UI-driven Just-In-Time replication, improved vault visibility, and granular vaulting controls, enhancing cyber vault operations and governance.
  • Expanded Nutanix AHV Protection
    Support for Directly Attached Volume Groups and datastore-level stream limits improves performance and scalability for AHV environments.
  • FIPS 140-3 Compliance
    Enhanced cryptographic standards for Windows and Linux agents help organizations meet strict regulatory requirements.
  • Expanded Microsoft 365 Protection Coverage
    Cohesity Cloud Protection Service now includes backup and recovery for Microsoft 365 Groups and Exchange Online Recoverable Items folders, which support In-Place Hold, eDiscovery Hold, Litigation Hold, and deleted item retention. This closes a key compliance and recovery gap by extending protection beyond mailboxes, OneDrive, SharePoint, and Teams to include held and retained data often required for legal and regulatory scenarios.
  • Kubernetes and AKS Enhancements
    Cohesity Cloud Protection Service now delivers application-consistent backups for Azure Kubernetes Service, along with granular recovery of Persistent Volume Claims at the file and folder level. This improves recovery precision for containerized workloads and reduces downtime for stateful applications.
  • Cross-Environment VM Recovery
    Organizations can now recover virtual machines between on-premises environments and Azure VMware Solution or VMware Cloud on AWS. This adds flexibility to disaster recovery strategies and supports hybrid mobility without requiring workload replatforming.

Nutanix

AI Infrastructure and Hybrid Flexibility
Nutanix is heavily investing in AI infrastructure and ecosystem expansion following .NEXT 2026. Check out our latest blog recapping the full list of .Next announcements.

View full Nutanix update
  • Expanded External Storage Integrations
    New integrations with Dell PowerStore, NetApp ONTAP, and Lenovo ThinkSystem broaden storage flexibility. This allows organizations to leverage existing investments while adopting Nutanix HCI.
  • Agentic AI Platform and NKP Metal
    Nutanix introduced a full-stack AI platform integrating compute, storage, networking, and Kubernetes. NKP Metal enables Kubernetes on bare metal, optimizing performance for GPU-intensive AI workloads.
  • Unified Storage 5.3 for AI Workloads
    Object storage is now optimized for AI data lakes with multi-tenant scaling, smart tiering, and future RDMA acceleration, supporting high-throughput AI pipelines.
  • Data Lens 2.0 On-Prem Deployment
    Security analytics now run fully on-premises, including air-gapped environments. This is critical for organizations with sovereignty or compliance requirements that prohibit SaaS-based security tools.
  • Database Automation with MongoDB Integration
    Integration with MongoDB Ops Manager enables automated provisioning and lifecycle management, reducing operational overhead for enterprise databases.

Everpure (Pure Storage)

High-Performance Storage for AI and Critical Workloads
Pure Storage, now branded EverPure, is focusing on extreme performance and reliability.

View full Everpure (Pure Storage) update
  • FlashArray//ST Raises the Ceiling for High-Performance Workloads
    The new FlashArray//ST is designed to deliver up to 18 million IOPS with consistently low latency for performance-intensive workloads such as AI training, inference pipelines, and real-time analytics. This gives infrastructure teams a stronger option for workloads where storage bottlenecks directly affect application responsiveness and business outcomes.
  • Enterprise Resilience Remains Core to the Platform
    FlashArray//ST retains the high-availability capabilities common across the FlashArray platform, including redundant components, active-standby controllers, and immutable, space-efficient snapshots. That matters because organizations do not have to trade resilience and recoverability for raw performance when supporting critical data-intensive applications.

Nerdio

Hybrid VDI Modernization Path
Nerdio is expanding desktop virtualization into hybrid environments.

View full Nerdio update
  • Nerdio Extends Desktop Orchestration to Nutanix AHV
    Nerdio Manager now extends desktop orchestration and Azure Virtual Desktop-style management to on-premises Nutanix AHV environments. This gives organizations a new way to modernize desktop operations without requiring a full move to public cloud infrastructure.
  • The Alliance Creates a Practical Migration Path for Legacy VDI
    This is especially relevant for organizations facing Citrix or Omnissa renewals and looking for a lower-friction alternative that preserves existing infrastructure investments. With private preview underway and general availability expected later this year, the offering provides a bridge strategy for teams that want modernization and cost control without going all-in on cloud VDI.

VMware

Automated Certificate Lifecycle Management
VMware continues incremental operational improvements.

View full VMware update
  • VCF 9.0.2 Adds Automatic Renewal for VMCA-Issued Certificates
    Effective with VMware Cloud Foundation 9.0.2, SSL certificates for vCenter and ESX that are issued by the VMware Certificate Authority are automatically renewed as expiration approaches. This reduces the risk of service disruption caused by missed certificate maintenance and lowers operational overhead for infrastructure teams.
  • Renewal Behavior Depends on Certificate Type and VMCA Mode
    vCenter Machine SSL certificates are automatically extended by two years when they are within five days of expiration, while supported ESX host certificates are extended by five years when they are within ten days of expiration. To benefit from this automation, environments must be using VMCA mode set to vmca rather than custom, which makes configuration review an important administrative step.

What’s New in Microsoft Cloud?

Azure

Azure: AI Expansion, Secure Infrastructure, and Operational Guardrails

Microsoft continues to deepen its AI platform while tightening security and infrastructure controls across Azure.

  • GPT-5.4 and Microsoft AI Models in Foundry
    GPT-5.4 is now available in Microsoft Foundry alongside Microsoft’s in-house MAI models, giving organizations flexibility in model selection for application development and automation. This matters because teams can optimize for cost, performance, or governance requirements while building AI-driven workloads tied to enterprise data.
  • Agent Service Enables Always-On AI Operations (GA)
    Microsoft Foundry Agent Service is now generally available, enabling secure, persistent AI agents that can take actions, access enterprise data, and support real-time voice interactions. This introduces new operational and governance considerations as agents move from passive assistants to active participants in business workflows.
  • Confidential Computing with Intel TDX (GA)
    Hardware-level encryption for Azure VMs using Intel TDX ensures data remains protected even from the underlying cloud infrastructure. This is especially critical for regulated industries handling sensitive data such as financial records, healthcare data, and government workloads.
  • Azure Firewall Draft Mode for Safer Policy Changes
    Firewall rule updates can now be staged and validated before deployment, reducing the risk of outages or unintended exposure. This improves operational control and aligns with change management and compliance requirements.
  • Default Outbound Internet Access Removed for New VNets
    New virtual networks no longer include default outbound internet access, requiring explicit configuration. This strengthens security posture by default, but organizations must validate connectivity requirements to avoid breaking application dependencies.
  • Azure IaaS Resource Center and Maximize ROI AI Hub
    Microsoft introduced centralized hubs for infrastructure best practices and AI investment optimization. These resources help organizations improve resilience, cost efficiency, and governance across compute, storage, and AI workloads.

Copilot

Copilot: Multi-Model AI, Agents, and Workflow Integration

Microsoft 365 Copilot is evolving into a multi-model, agent-driven productivity platform embedded across Microsoft 365.

  • Copilot Cowork Expands to Frontier Tenants
    Copilot Cowork is now available in Frontier tenants and can be accessed via the “All Agents” entry point. This expands early access to multi-agent collaboration scenarios, allowing organizations to test how multiple AI agents interact across workflows and shared data contexts.
  • Anthropic Claude Sonnet Integration in Copilot Chat
    Claude Sonnet is now available for licensed users within Copilot Chat, but requires explicit admin opt-in as Anthropic models are disabled by default. This introduces multi-model flexibility while requiring governance decisions around model usage, data exposure, and output validation.
  • Granular Admin Control for Third-Party AI Models
    Admins can assign third-party models, such as Anthropic, to specific users or groups via the Microsoft Admin Center. This enables controlled rollout strategies and supports compliance requirements by limiting which users can access external AI processing.
  • PowerPoint Copilot Enhancements for Web
    Microsoft 365 Copilot in PowerPoint for the web now supports full presentation creation and editing through natural language while preserving formatting and brand assets. Rolling out globally by April, this increases productivity but also raises considerations around content accuracy, brand governance, and data used in the prompt context.
  • Word Agent Becomes Primary Copilot Interface
    Microsoft is shifting Word’s Copilot experience to an agent-first model, with the Word Agent embedded in the chat pane. This centralizes document interaction and changes how users engage with AI for content creation and editing workflows.
  • Declarative Agents Upgrade to GPT 5.2
    Copilot Declarative Agents will automatically upgrade to GPT 5.2, improving reasoning and multi-step task execution. However, Microsoft warns that output variability may impact workflows dependent on consistent logic, requiring testing for regulated or deterministic processes.
  • Copilot Notebooks for Excel (Public Preview)
    Users will be able to generate and edit Excel spreadsheets directly from notebook content, with rollout between March and April. This bridges structured data creation with AI-driven context, increasing productivity but expanding the scope of data processed by Copilot.
  • Expanded Copilot Notebooks Capabilities
    Frontier Public tenants will gain features such as chat interactivity, study guides, SharePoint grounding, integration with Word and PowerPoint agents, sharing to Microsoft 365 Groups, and mind mapping. These enhancements deepen Copilot’s integration with enterprise content and collaboration data.
  • Natural Language Email Triage in Outlook
    Copilot now supports email triage actions using natural language across Outlook platforms. This allows users to organize, prioritize, and respond to emails more efficiently, but introduces risk around automated handling of sensitive communications.
  • Federated Connectors for External Data Access
    Copilot can now access external platforms like Notion and Canva through federated connectors. Admins retain control over connector visibility and compliance, making governance essential to prevent unintended data exposure across third-party systems.
  • Planner Agent for Task and Work Management
    The Planner Agent enables users to create, update, and manage tasks directly within Copilot chat using natural language. This embeds AI into operational workflows, improving efficiency while increasing dependency on accurate task interpretation.
  • Researcher Agent Enhancements and Model Council
    Researcher Agent now supports infographic export and enhanced document outputs, while the Model Council feature uses multiple models from Anthropic and OpenAI to validate results. This improves output quality and reliability, especially for complex research scenarios.
  • Persistent Chat Sessions and Infinite History
    Copilot chat now automatically creates session entries for each prompt and will introduce infinite scroll for chat history. This improves continuity and usability but increases retained conversational data, which may have compliance and retention implications.
  • Voice Interaction Across Microsoft 365 Apps
    Copilot is introducing voice chat across desktop, web, and mobile apps including Word, PowerPoint, and Outlook. This capability cannot be disabled by admins, raising governance considerations for environments with strict data handling requirements.
  • Hands-Free “Hey Copilot” Activation on Windows
    Users can enable voice activation on Windows devices, allowing hands-free interaction with Copilot. The feature processes audio locally without recording, which helps address privacy concerns while enabling new user interaction models.
  • Copilot Pages Code Preview Governance Controls
    Admin-controlled AI-generated code previews are now available within Copilot Pages. This allows organizations to enable or restrict AI-assisted code generation, supporting governance for development and automation scenarios.
  • Email File Upload Support for Contextual Prompts
    Copilot now supports uploading .eml and .msg files, allowing users to include full email context in prompts. This expands analytical capabilities but increases the volume of potentially sensitive data processed by AI.
  • Interactive AI Podcasts with Real-Time Voice Engagement
    Copilot will enable real-time voice interaction within podcast-style experiences, allowing users to ask questions during audio playback. This introduces a new content consumption model that blends passive listening with active AI engagement.
  • Copilot License Request Justification Workflow
    License requests now include an optional business justification field, giving admins more context during approval. This supports governance, cost control, and prioritization of high-value use cases.
  • AI Watermarking for Generated Media
    Organizations can apply watermarking policies to AI-generated or modified audio and video content. This is critical for compliance, transparency, and content authenticity in regulated or public-facing scenarios.

What to Consider: Copilot is rapidly evolving into a multi-model, multi-agent platform embedded across productivity workflows, making governance, data protection, and model control essential for enterprise adoption at scale.

Copilot Studio

Copilot Studio: Advanced Agent Orchestration, Evaluation, and Governance

Microsoft Copilot Studio is rapidly maturing into a full lifecycle platform for building, evaluating, and governing enterprise AI agents, with major investments in multi-agent orchestration, evaluation automation, and model flexibility.

  • AI-Based Sentiment Analysis for Agent Experience Insights
    Copilot Studio introduces AI-driven sentiment analysis to evaluate user emotions during agent interactions. When combined with traditional CSAT metrics, this provides deeper insight into user satisfaction and helps identify friction points in conversational workflows, especially for customer-facing or support scenarios.
  • Multi-Turn Conversation Evaluation (Preview)
    Makers can now evaluate agent performance across entire conversations rather than isolated responses. This improves accuracy in assessing real-world agent behavior, particularly for complex workflows involving multi-step reasoning and contextual continuity.
  • Tool and Topic Invocation Grader for Execution Validation
    A new grader verifies whether agents invoked the correct tools or topics during execution, not just whether the response was accurate. This strengthens validation of orchestration logic, which is critical for agents performing actions across systems or workflows.
  • Evaluation Datasets from Real Conversations
    Makers can now generate structured evaluation datasets directly from production interactions instead of relying on synthetic test cases. This enables more realistic testing and continuous improvement of agents based on actual usage patterns and data.
  • Analyst Role for Secure Access to Agent Insights
    The new Analyst role allows teams to access agent analytics without permission to modify configurations. This supports separation of duties, enabling business analysts and stakeholders to review performance data while maintaining governance over agent design and deployment.
  • Multi-Agent Orchestration with Fabric Integration
    Copilot Studio agents can now work alongside Microsoft Fabric agents to reason over enterprise data at scale. This allows organizations to connect AI agents directly to analytics platforms, improving accuracy and enabling data-driven decision-making without custom engineering.
  • Microsoft 365 Agents SDK for Cross-Platform Orchestration
    Teams can orchestrate Copilot Studio agents with Microsoft 365 agents using the Agents SDK. This unifies agent experiences across productivity and business applications, enabling more cohesive automation strategies.
  • Agent-to-Agent (A2A) Communication Support
    Copilot Studio now supports direct communication and task delegation between agents using an open protocol. This enables distributed workflows where specialized agents collaborate, increasing scalability and flexibility in complex automation scenarios.
  • Immersive Prompt Builder (GA)
    The Prompt Builder is now generally available, allowing makers to edit prompts, switch models, add inputs, and test changes directly within the Tools tab. This streamlines development workflows and reduces friction in prompt engineering and iteration.
  • Granular Content Moderation Controls for Prompts
    Makers can now configure sensitivity levels for harmful content detection in prompts. This is especially important for regulated industries where default moderation settings may block legitimate use cases, requiring fine-tuned control.
  • Expanded Model Support Including Anthropic Options
    The Prompt Tool now supports Anthropic Claude Opus 4.6 and Claude Sonnet 4.5 in paid experimental preview. This expands model choice, allowing organizations to align specific workloads with the most appropriate AI model for performance, cost, or compliance.
  • Connector Improvements for ServiceNow and Azure DevOps (GA)
    Enhancements to these connectors improve agents’ ability to retrieve and interpret operational data such as tickets and work items. This increases the reliability and usefulness of agents in IT service management and DevOps workflows.
  • Evaluation Automation APIs (GA)
    New APIs enable programmatic evaluation of agents through Power Platform connectors, supporting integration into CI/CD pipelines. This allows organizations to continuously validate agent performance and enforce quality standards before deployment.
  • Real-Time Meeting Integration for Teams Agents
    Agents can now access live meeting transcripts and group chat in Microsoft Teams. This supports real-time assistance scenarios such as answering questions, surfacing relevant data, and tracking decisions during meetings.
  • Expanded MCP and Apps SDK Integration
    Model Context Protocol (MCP) and Apps SDK enhancements improve how agents connect to external business systems. This allows agents to move beyond responses and take actions across enterprise applications, increasing their operational value.
  • Broader Model Portfolio for Performance Tuning
    Additional models, including Grok 4.1 Fast, GPT-5.3 Thinking, and GPT-5.4 Instant, are now available in paid experimental preview. This gives makers flexibility to optimize for speed, cost, or reasoning capability depending on the use case.

Why It Matters: Copilot Studio is evolving into an enterprise-grade AI agent platform, where success depends on not just building agents, but rigorously evaluating, governing, and orchestrating them across systems, data, and workflows.

Defender XDR

Defender XDR: AI-Driven Security Operations and Unified Threat Visibility

Microsoft Defender XDR continues to evolve into a unified, AI-powered SOC platform, combining cross-domain visibility with automation and deeper integration across identity, cloud, and data security.

  • Security Copilot Embedded in Defender Portal
    Microsoft introduced a conversational Security Copilot experience directly within the Defender portal, enabling analysts to investigate incidents using natural language. This allows teams to follow investigation threads across alerts, identities, endpoints, and cloud resources without leaving the console, improving efficiency and reducing context switching.
  • Expanded Container Security in Azure Government (GA)
    Defender for Cloud now delivers full container security capabilities in Azure Government, including agentless Kubernetes discovery, vulnerability assessment, attack path analysis, and runtime threat protection. This brings parity with commercial environments and is critical for public sector organizations with strict compliance and data residency requirements.
  • Unified Defender Platform Experience
    Microsoft continues consolidating Defender for Cloud into the broader Defender XDR platform, delivering a more unified portal experience. Combined with Security Copilot and cross-signal threat intelligence, this enables more cohesive detection and response across hybrid and multi-cloud environments.
  • Security Alert Triage Agent Expansion
    The triage agent now extends beyond phishing to include identity and cloud alerts, automatically determining whether alerts are legitimate threats or false positives. It provides step-by-step reasoning in natural language, improving analyst decision-making and reducing manual triage effort.
  • Identity Security Dashboard (Public Preview)
    A new dashboard centralizes identity security posture across Entra ID, Active Directory, SaaS apps, and PAM/IGA systems. With maturity scoring and unified visibility, security teams can better assess identity risk and prioritize remediation across both human and non-human identities.
  • Predictive Shielding with Proactive User Containment (GA)
    Defender XDR can now identify at-risk credentials before exploitation and automatically apply containment actions. This proactive approach reduces the likelihood of account compromise and requires organizations to review policies to ensure appropriate automated responses.
  • Purview DLP Integration with AI Summaries (Preview)
    AI-generated summaries from the Microsoft Purview Data Security Triage Agent will appear directly within DLP alerts in Defender. This accelerates investigation workflows and ensures sensitive data incidents across workloads like Exchange, SharePoint, and endpoints are triaged more efficiently without switching tools.

Entra ID

Entra ID: Passwordless Authentication and Stronger Identity Governance

Microsoft Entra ID is advancing passwordless authentication while tightening policy enforcement and audit visibility across hybrid identity environments.

  • Passkey Profiles and Synced Passkeys (FIDO2)
    Entra ID now supports passkey profiles and synced passkeys for tenants with FIDO2 enabled, automatically migrating existing configurations to a default profile. Passkeys on Windows enable phishing-resistant, passwordless authentication using Windows Hello across both managed and unmanaged devices, significantly reducing credential theft risk.
  • Agent 365 Replaces Legacy Agent Management
    Agent 365 will replace the Agent Registry and Agent Collections in the Entra admin center starting in May. This simplifies agent lifecycle management and aligns identity-based agent governance with broader Microsoft 365 and AI agent strategies.
  • Registration Campaigns Expand to Passkeys
    Microsoft Registration Campaigns now support passkeys as an authentication method, enabling organizations to prompt users during sign-in to enroll in phishing-resistant credentials. This helps accelerate the adoption of stronger authentication methods without requiring separate enrollment campaigns.
  • Conditional Access Enforcement Tightening
    Conditional Access policies targeting all resources will now be enforced even when exclusions are configured. This change strengthens security posture but requires careful policy review to avoid unintended access disruptions or lockouts.
  • Improved Audit Logging for Authentication Policies
    Audit logs now display only the specific properties that were changed rather than full policy payloads. This improves clarity for security investigations and simplifies compliance reporting by making policy changes easier to track and validate.
  • Stronger Hybrid Identity Protections (Coming June 2026)
    Microsoft will block hard-match synchronization for role-assigned users in hybrid environments to reduce account takeover risk. This enforces stricter identity governance controls and requires organizations to review synchronization and privilege assignment strategies ahead of enforcement.

Exchange Online

Exchange Online: High-Volume Messaging and Legacy Authentication Transition

Exchange Online is evolving to support modern high-volume communication needs while continuing to phase out legacy authentication methods.

  • High Volume Email (HVE) for Internal Messaging (Starting May 2026)
    High Volume Email (HVE) enables organizations to send large volumes of internal email without standard recipient rate limits using a pay-as-you-go model. This is particularly impactful for organizations currently maintaining on-premises Exchange servers solely for internal relay scenarios, as HVE provides a cloud-native alternative that can reduce infrastructure footprint and operational overhead.
  • SMTP AUTH Basic Authentication Deprecation Timeline Update
    Microsoft confirmed that SMTP AUTH Basic Authentication behavior will remain unchanged through December 2026, after which it will be disabled by default for existing tenants, with admin override still available. Organizations relying on legacy devices, printers, or applications must begin migrating to OAuth or alternative submission methods to avoid service disruption and align with modern security and compliance standards.

Exchange Server

Exchange Server: Modern Authentication and Automation Enhancements

Microsoft Exchange Server continues to evolve its hybrid role with improved security and automation capabilities in the upcoming Subscription Edition updates.

  • Exchange Server SE CU1 Introduces Kerberos for Server-to-Server Authentication
    Exchange Server Subscription Edition CU1, expected in the first half of 2026, will add Kerberos support for server-to-server authentication. This enhances security by replacing legacy authentication methods with stronger, ticket-based authentication, reducing the risk of credential interception in hybrid and on-premises environments.
  • New Admin API Enables Automation and Modern Management
    CU1 will also introduce a new Admin API designed for automation scenarios, enabling organizations to script and manage Exchange operations more efficiently. This supports modern operational practices such as infrastructure as code and reduces manual administrative overhead in complex environments.
  • Modern Servicing Model Requires Timely Updates
    Organizations running Exchange Server SE in hybrid configurations must stay current with cumulative updates under the Modern Servicing model. Delaying CU1 adoption could introduce compatibility, security, and supportability risks, making proactive update planning critical.

Fabric

Fabric: Data Platform Enhancements for Scale, AI, and Governance

Microsoft Fabric continues to expand its capabilities across data engineering, analytics, and governance, with a focus on flexibility, automation, and AI-driven workloads.

  • SQL Migration Assistant for Fabric (Preview)
    Microsoft is introducing a migration assistant to simplify moving SQL databases into Fabric.
  • ANY_VALUE() Support in Data Warehouse
    Fabric now supports ANY_VALUE() to simplify query logic when grouping results.
  • Unstructured Data Support with AI Functions (Preview)
    Built-in AI functions will enable analysis of unstructured text directly within Fabric Data Warehouse.
  • Customer-Managed Keys for Workspaces (BYOK) (Preview)
    Fabric introduces workspace-level encryption using customer-managed keys to support compliance requirements.
  • Job Failure Notifications for Admins
    Admins can now receive alerts when scheduled jobs fail, improving operational visibility.
  • Sensitivity Labels for Public APIs
    Sensitivity labels are now supported in Fabric public APIs to extend data classification and protection.
  • Compute Auto-Scaling for SQL Workloads (Preview)
    New auto-scaling options help optimize cost and performance for SQL databases in Fabric.
  • Capacity Overage Support (Preview)
    Fabric introduces capacity overage to allow workloads to continue running during peak demand.
  • Lakehouse Auto-Binding in Git (Preview)
    Fabric notebooks will support automatic Lakehouse binding when integrated with Git workflows.
  • Customer-Managed Keys in Fabric SQL Database
    CMK support is now available for Fabric SQL databases to enhance data protection and compliance.

Intune

Intune: Endpoint Security, Automation, and Privilege Control

Microsoft Intune continues to enhance endpoint management with a focus on automation, least privilege, and operational efficiency across hybrid environments.

  • Hotpatching Control and Default Enablement Shift
    Intune introduces a tenant-level opt-out for hotpatch updates starting in April, ahead of hotpatching becoming the default for Windows Autopatch devices. This significantly reduces reboot requirements and accelerates deployment of critical security updates across managed endpoints.
  • Unified Admin Tasks Experience
    Intune now consolidates administrative actions such as Endpoint Privilege Management requests and Defender remediation tasks into a single workflow. This improves operational efficiency and reduces friction for IT teams managing endpoint security and access.
  • Expanded Endpoint Privilege Management for AVD
    Endpoint Privilege Management now supports Azure Virtual Desktop session hosts, enabling consistent enforcement of least-privilege access across both physical and virtual Windows environments. This is critical for reducing the attack surface in distributed and hybrid workforce scenarios.
  • Support Assistant Expansion and App Ecosystem Growth
    Support Assistant is now available to all authenticated users in the Intune admin center, improving self-service troubleshooting and reducing reliance on privileged roles. Continued expansion of protected app integrations also strengthens the Intune ecosystem and enhances secure application management.

Microsoft Edge for Business

Microsoft Edge for Business: AI-Powered Browsing and Cross-Tenant Data Protection

Microsoft Edge for Business is enhancing productivity and security by embedding Copilot experiences and expanding cross-tenant data protection controls.

  • Copilot-Inspired New Tab Experience
    Edge introduces a redesigned new tab page that combines search, chat, and work content into a single interface, streamlining access to productivity tools.
  • Cross-Tenant MAM Policy Support
    Edge now supports Intune Mobile Application Management policies across tenants, enabling secure data access and protection on devices managed by different organizations.
  • Copilot Chat with Cross-Context Summarization
    Copilot Chat in Edge can summarize and provide context across browser tabs, Microsoft 365 documents, and YouTube videos, improving research and workflow efficiency.

Microsoft 365 Apps

Microsoft 365 Apps: Update Channel Simplification

Microsoft 365 Apps is streamlining update channels to simplify deployment and servicing.

  • Retirement of Semi-Annual Enterprise Channel (SAEC)
    The Semi-Annual Enterprise Channel will be retired on April 20, with new deployments limited to Current Channel and Monthly Enterprise Channel. Existing SAEC devices remain supported and will continue receiving updates aligned with the Monthly Enterprise Channel.

What to Consider: Organizations should align future deployment strategies with the remaining update channels to maintain consistency and supportability.

Microsoft Loop

Microsoft Loop: Governance and Lifecycle Management Enhancements

Microsoft Loop is strengthening governance and lifecycle controls as adoption of collaborative workspaces grows.

  • Workspace Governance with Microsoft 365 Groups
    New Loop workspaces can be required to connect to existing Microsoft 365 Groups, aligning governance with SharePoint-backed collaboration. This ensures consistent policy enforcement, access control, and lifecycle management across collaborative content.
  • Retention and Deletion Controls for User-Owned Workspaces
    Microsoft is rolling out retention and deletion policies for user-owned Loop workspaces, allowing admins to preserve content when users leave the organization. This is critical for compliance, eDiscovery, and maintaining access to business-critical information.
  • Retirement of Copilot-Generated Recaps
    Copilot-generated recaps are being retired, while manual recap editing remains available. Organizations relying on automated summaries may need to adjust workflows or validate alternative documentation practices.

OneDrive

OneDrive: Sync, Recovery, and User Experience Improvements

OneDrive continues to improve day-to-day file management across Windows, web, and macOS. This month’s updates focus on sync path flexibility, clearer recovery behavior, and a more polished end-user experience.

  • Custom local sync folder names on Windows
    Admins can now set a custom local OneDrive sync folder name on Windows to help reduce path length issues. New users get the custom name automatically, while existing users must unlink and relink OneDrive for the change to apply.
  • Cloud-deleted files no longer appear in local recycle bins
    Files deleted from OneDrive in the cloud will no longer show up in local recycle bins. They remain recoverable through the web, which clarifies where users and admins need to go for recovery.
  • Undo and Redo for PDF annotations in OneDrive for web
    OneDrive for web now supports Undo and Redo for PDF annotations. This makes document review and markup less error-prone for users collaborating on PDFs.
  • Redesigned Activity Center for macOS
    OneDrive for macOS introduces a redesigned Activity Center that better aligns with macOS conventions. The update improves sync visibility, accessibility, and error handling for Mac users.

Outlook

Outlook: Mobile Enhancements and Migration Timeline Extension

Outlook updates this month focus on improving mobile usability and giving organizations more time to prepare for the new Outlook experience. These changes balance end-user productivity with administrative control and compliance planning.

  • Enhanced meeting responses on Outlook Mobile
    Users can now decline meetings while proposing a new time and use the Follow response option directly from mobile. This improves scheduling flexibility and reduces back-and-forth communication.
  • Automatic sensitivity labeling on mobile
    Outlook for iOS and Android now supports recommended and auto-applied sensitivity labels during email composition. This strengthens data protection by helping ensure emails are properly classified before sending.
  • New Outlook migration timeline extended
    Microsoft has delayed the forced transition to the new Outlook from April 2026 to March 2027. This gives admins an additional 12 months to validate features, run pilots, and plan migrations without disrupting users.

Power BI

Power BI: Mobile Copilot and Web Modeling Enhancements

Power BI is introducing lightweight but meaningful updates focused on mobile interaction and developer-centric modeling experiences.

  • Copilot chat in Power BI mobile (Preview)
    Users can now interact with Copilot directly inside reports on the Power BI mobile app. This enables on-the-go data exploration using natural language, improving accessibility to insights without requiring desktop access.
  • TMDL View on the Web
    TMDL View will soon be available in the browser, enabling a code-first semantic modeling experience without needing desktop tools. This gives developers more flexibility to build and manage models directly in web environments. 

Power Platform

Power Apps — UI Standardization and Real-Time Data Access

Power Apps updates focus on standardizing the user experience and improving data responsiveness for offline-first scenarios.

  • Modern UI becomes mandatory for model-driven apps
    The refreshed Power Apps interface is now the default with no option to revert. This enforces consistency across environments but may require user retraining and validation of customizations.
  • Real-time Dataverse access for offline apps
    Offline-first canvas apps can now access the latest Dataverse data instantly when online. This eliminates sync delays and improves data accuracy for users switching between offline and connected states.
Power Automate — Monitoring and Licensing Optimization

Power Automate enhancements focus on improving operational visibility and reducing licensing costs for high-volume workflows.

  • Work queue alerts in public preview
    Admins can configure alerts for work queues directly from the Power Platform admin center. This enables proactive monitoring of queue performance and faster response to processing issues.
  • Flow groups for shared licensing capacity
    Flow groups allow up to 25 cloud flows to share Process license capacity. This helps optimize licensing costs for organizations running multiple high-volume workflows without needing dedicated licenses per flow.

Purview

Purview: Expanded Data Governance and AI-Driven Security Insights

Microsoft Purview continues to strengthen data governance, compliance enforcement, and security visibility across Microsoft 365 and AI workloads. Updates this month focus on closing labeling gaps and improving investigation and DLP clarity.

  • Default labeling for SharePoint data at rest
    Purview now applies default sensitivity labels to existing SharePoint files, not just new content. This closes a key compliance gap and ensures legacy data is protected under labeling policies.
  • Hard delete with approval for retained data
    Admins can permanently delete retained OneDrive and SharePoint files through approval workflows. This enables controlled exceptions for legal scenarios while maintaining audit trails.
  • Retention for Teams Phone call logs
    Retention and deletion policies now support Teams Phone call logs. This extends compliance coverage to voice data subject to regulatory requirements.
  • Endpoint DLP events in investigations
    Endpoint DLP events are now available in Purview Data Security Investigations. This improves visibility and accelerates incident response across endpoints and cloud data.
  • Data Security Posture Management enhancements
    Purview adds unified visibility across data and AI environments with improved reporting and integrations. This helps organizations better assess and manage data risk.
  • Item-level risk assessments for SharePoint
    Teams can now investigate and remediate risks at the file level in SharePoint. This enables more precise control over sensitive content.
  • AI-powered DLP alert summaries
    Copilot generates clear explanations for DLP alerts. This speeds up triage and helps analysts quickly understand risk and impact.

SharePoint Online

SharePoint Online: UX Redesign, Governance Changes, and AI Integration

SharePoint Online updates focus on a redesigned user experience, stricter governance controls, and deeper AI integration across content and workflows.

  • New SharePoint experience and navigation
    The new SharePoint experience introduces a redesigned information architecture, updated app bar with Discover, Publish, and Build destinations, and a cohesive neutral design language. Organizations should evaluate this update in a test tenant before broad rollout, particularly if they rely on customized navigation or branded site experiences.
  • Delegated Restricted Access Control (RAC)
    RAC management can now be delegated to site admins with required justification. This improves governance flexibility while maintaining oversight and auditability.
  • Retirement of Add-ins and 2013 Workflows
    Legacy SharePoint Add-ins and 2013 Workflows were retired on April 2, 2026. Any unmigrated solutions have stopped working, requiring transition to SPFx and Power Automate.
  • New sharing “hero link” experience
    A unified sharing link now controls all access for a file. This simplifies permission management and reduces confusion from multiple link types.
  • Content Security Policies enforcement
    CSP enforcement is now active and may impact custom SPFx solutions. Organizations should validate customizations to avoid functionality issues.
  • Custom AI skills in SharePoint
    Reusable AI-powered tasks can now be created and stored as Markdown. This enables scalable automation of multi-step content workflows.
  • AI-powered FAQ web part enhancements
    The FAQ web part now includes AI-driven suggestions and improved content grounding. This helps keep knowledge bases accurate and easier to maintain.
  • Unified workflows powered by Power Automate
    SharePoint workflows are now aligned with Teams using a unified Power Automate experience. This improves consistency across collaboration tools.
  • Microsoft Lists as agent knowledge sources
    Lists can now be used as data sources for custom AI agents. This expands how structured data can power automation and insights.

Teams

Teams Chat & Channels — UX Improvements and Collaboration Enhancements

Microsoft Teams continues refining chat organization, collaboration features, and cross-app alignment. These updates focus on usability, consistency, and governance.

  • Planner tabs in Shared and Private Channels
    Planner is now supported in Shared and Private Channels. This expands task management into more collaboration scenarios without requiring standard channels.
  • Do Not Disturb alignment with Windows
    Teams now respects Windows Do Not Disturb settings. This ensures a more consistent notification experience across the OS and Teams.
  • Slash commands for workflow creation
    Users can create workflows directly from chats and channels using slash commands. This simplifies automation and reduces friction in initiating processes.
  • Centralized draft message management
    Users can now view all unsent messages in one place. This improves visibility and reduces the risk of lost or forgotten drafts.
  • Whiteboard storage alignment with SharePoint
    Whiteboards created in channel tabs will be stored in the associated SharePoint site starting September. This improves compliance, access control, and lifecycle management.
  • Emoji and reaction sync across devices
    Recently used emojis and reactions will sync across devices. This provides a more consistent user experience.
  • Private Channel app support on pause
    Support for apps in Private Channels has been delayed before GA. Admins should review governance and app policies in preparation for future rollout.
  • New chat sections for organization
    Muted chats and Meeting chats will appear as separate sections. Users can toggle these views to better organize conversations.
  • Collaborative Notes in chats
    A new Notes tab enables real-time co-authoring of agendas and action items. This enhances lightweight collaboration directly within chats.
  • Updated badge counts and notifications
    Teams will refine badge counts to highlight relevant activity like mentions and unread chats. This improves signal-to-noise for users.

Quick Take: These updates focus on reducing clutter and improving collaboration, while continuing to align Teams with Microsoft 365 compliance and data management standards.

Teams Meetings — AI Recaps, Accessibility, and Meeting Quality Enhancements

Microsoft Teams Meetings updates focus on AI-driven recaps, improved accessibility, and better meeting quality across devices and platforms.

  • AI-powered video recaps and summaries
    Teams will add video highlight clips to intelligent meeting recaps alongside AI summaries. This helps users quickly review key moments without watching full recordings.
  • AI recaps without recordings or transcripts
    AI-generated recaps will be available even when recordings or transcripts are disabled. This supports compliance-sensitive environments while still delivering meeting insights.
  • Automatic language detection for captions
    Teams will automatically detect spoken language for captions and transcripts. This reduces setup effort and improves accuracy in multilingual meetings.
  • Expanded webinar and town hall capacity
    New capacity packs scale interactive events up to 100,000 attendees. This supports larger enterprise communications and external events.
  • Improved meeting experience features
    Enhancements include macOS-native screen sharing, collaborative annotation requests, private organizer chat, and pre-join audio testing. These updates improve usability and meeting readiness.
  • External meeting bot detection and control
    Teams will detect and label external meeting assistant bots, allowing organizers to approve or remove them. Admin policies will govern bot access, strengthening meeting security.
  • Custom AI summaries for Copilot users
    Users can generate personalized meeting summaries using custom templates. This improves relevance and usability of AI-generated notes.
  • Direct Guest Join media improvements
    Enhanced video quality and support for up to 16 participants in a 4×4 grid will improve cross-platform meetings. This is especially relevant for interoperability with Zoom, Google Meet, and Cisco devices.

Why It Matters: Teams is evolving meetings into AI-assisted experiences while addressing compliance, accessibility, and cross-platform collaboration requirements.

Teams Admin — Governance, Visibility, and Device Management Updates

Teams Admin updates focus on improving meeting security controls, expanding visibility into external interactions, and unifying device management.

  • Simplified meeting passcodes
    Admins can enable 8-digit numeric-only meeting passcodes. This simplifies user experience but should be evaluated against organizational security policies.
  • Teams Android device management transition
    Device management is moving to the Teams Rooms Pro Management portal. This unifies administration across Teams devices, with rollout starting in April and completing by September.
  • External Domains Anomalies Report– By late May, a new report will identify unusual external communication patterns. This enhances security monitoring and helps detect potential data exfiltration or risky interactions.
  • Automatic work location detection
    Teams can automatically set user work locations based on Wi-Fi or peripherals. This opt-in feature improves coordination but requires admin configuration and respects working hours.
Teams Rooms — Meeting Intelligence and Room Experience Enhancements

Teams Rooms updates focus on improving in-room meeting intelligence, administrative insights, and scheduling flexibility.

  • Live transcription with speaker attribution (Android)
    Teams Rooms on Android will support live transcription with speaker attribution, timestamps, and optional translation. This enhances accessibility and meeting documentation for in-room participants.
  • Building-level insights in the management portal
    In April, new insights will appear in the Teams Rooms Pro Management portal. This gives admins better visibility into room usage and optimization opportunities.
  • Ad-hoc room reservations (Windows)
    Users can reserve rooms مباشرة from the console for immediate meetings. Admins can control this feature to align with scheduling policies.
Teams Phone — Flexible Number Assignment

Teams Phone continues to expand telephony flexibility within Microsoft 365 environments.

  • Multiple phone numbers per user
    Teams now supports assigning multiple phone numbers to a single user account. This enables more flexible call routing, supports multiple roles or regions, and simplifies telephony management for complex user scenarios.

Quick Take: This update improves flexibility for organizations with advanced calling needs, especially in global or multi-role environments.

Windows

Windows: Licensing Flexibility and Forced Update Policy

Windows updates this month focus on expanded licensing flexibility and enforced lifecycle management for consumer devices.

  • Forced upgrade to Windows 11 25H2
    Unmanaged Windows 11 Home and Pro devices on version 24H2 will be automatically upgraded to 25H2. This is driven by the October 2026 end-of-support deadline, ensuring devices remain secure, while enterprise-managed devices are not impacted.
  • Licensing Mobility in CSP
    Microsoft introduced Licensing Mobility within the CSP program, allowing Software Assurance licenses for SQL Server and Remote Desktop Services to be used outside Azure in approved environments. This gives organizations more flexibility in hybrid and multi-cloud deployment scenarios.

 

Get in Touch with Us

Connect with an expert to learn what we can do for your business.

Request Access to Win Wires

Enter your work email to request access to the eGroup Win Wires repository.

By requesting access, you confirm you are using an approved business email domain. You’ll receive a secure, one-time login link after returning to the Win Wires page.

May 19–21, 2026 • Microsoft Virtual Roadshow Days • 1–5 PM EST