Microsoft 365 Updates and Retirements: What EDU & SLED IT Teams Need to Know
Share this post
Author
Microsoft 365 continues to evolve—and for education and state and local government IT teams, those changes can have real operational and security implications.
From the retirement of Exchange Web Services (EWS) to changes coming to Microsoft Entra ID, Microsoft Purview, Defender for Cloud Apps, and OneDrive, several important updates require IT teams to review configurations, identify affected users and applications, and plan migrations before deadlines arrive.
For organizations already balancing cybersecurity, infrastructure, compliance, and day-to-day IT operations, keeping up with Microsoft 365 changes can be a challenge.
We’ve pulled together the updates that matter most and what EDU and SLED IT teams should do next.
The bottom line: Don’t wait for a Microsoft retirement date to become an outage. Review your environment now, identify what is affected, and build the necessary changes into your IT and security roadmap.
Exchange Web Services (EWS) Retirement: Prepare for October 2026
What’s changing?
Microsoft has been moving customers away from Exchange Web Services (EWS) for years. Beginning October 1, 2026, Microsoft will begin disabling EWS requests to Exchange Online.
Microsoft originally announced in 2018 that it would stop making feature updates to EWS and encouraged developers to migrate to the Microsoft Graph API. Microsoft later announced the timeline for EWS retirement.
For organizations with custom applications or integrations still relying on EWS, now is the time to identify those dependencies and begin migrating.
Most custom EWS applications can be moved to Microsoft Graph, Power Platform, or Copilot Declarative Agents.
Who is affected?
Organizations with active EWS applications in their Microsoft 365 environment.
The Microsoft 365 Message Center can help identify applications that are currently using EWS.
Apple Mail for Mac and related applications are among the common applications associated with EWS activity. Microsoft is working with Apple on updates; organizations looking for the most secure configuration in the meantime should consider using an alternative such as Outlook for Mac.
What should IT teams do?
- Review your application portfolio. Identify applications that rely on EWS and determine whether the required update is owned by your organization or a third-party vendor.
- Prioritize application modernization. Build EWS migration into your engineering and application roadmap now rather than waiting until the retirement deadline.
- Review security controls. While EWS applications remain active, make sure MFA is enabled for users—including test accounts—and review other applicable security controls.
- Plan for EWS to be disabled. Once applications no longer depend on EWS, disable it in your tenant or enable Baseline Security Mode as appropriate.
Microsoft also provides open-source tools and tutorials to help organizations discover, analyze, and modernize EWS applications.
Microsoft Defender for Cloud Apps File Policies Are Retiring
What’s changing?
Microsoft is retiring file policies in Microsoft Defender for Cloud Apps on January 6, 2027.
After that date, DLP file policies configured in Defender for Cloud Apps will no longer be supported or enforced.
Microsoft is moving equivalent file policy capabilities for SharePoint and OneDrive into Microsoft Purview. Support for DLP policies covering non-Microsoft SaaS applications—including Box and Google Workspace—is also being introduced.
Who is affected?
Organizations currently using DLP file policies in Microsoft Defender for Cloud Apps.
If your organization doesn’t use these policies, no immediate action is required.
What should IT teams do?
Start by reviewing your existing file policies in Defender for Cloud Apps.
From there:
- Identify policies that need to remain in place.
- Map those policies to the appropriate Microsoft Purview DLP capabilities.
- Recreate and test the policies in Purview.
- Disable legacy policies that are no longer needed.
- Confirm that your organization has the necessary Microsoft Purview licensing.
For education and government organizations managing sensitive student, employee, financial, research, or constituent data, this is also a good opportunity to review where sensitive information lives and how it is being protected across Microsoft 365.
Microsoft Entra ID: Custom Controls Are Being Retired
What’s changing?
Microsoft is retiring Custom Controls in Microsoft Entra Conditional Access and moving organizations toward External MFA, a standards-based integration for third-party multifactor authentication providers.
The goal is to provide a more sustainable and interoperable approach to integrating external MFA solutions with Microsoft Entra ID.
Key dates:
- September 2026: Administrators can no longer create or modify Custom Controls.
- May 2027: Custom Controls are fully retired.
Who is affected?
Organizations currently using Custom Controls in Microsoft Entra Conditional Access policies.
If your organization isn’t using Custom Controls, no action is required.
What should IT teams do?
Review your Conditional Access policies and identify any that rely on Custom Controls.
If you find them:
- Configure your third-party MFA provider as an External Authentication Method.
- Update affected Conditional Access policies.
- Validate authentication flows.
- Confirm that the migration works as expected.
- Remove Custom Control references once migration is complete.
- Communicate the change to identity, security, and help desk teams.
For schools, universities, and government agencies, identity is one of the most important layers of your security environment. Changes to authentication and Conditional Access should be tested carefully before they affect users.
Microsoft Purview DLP: Instances Policy Location Is Retiring
What’s changing?
Microsoft is retiring the Instances policy location in Microsoft Purview Data Loss Prevention (DLP) on January 6, 2027.
The Instances location currently relies on Microsoft Defender for Cloud Apps file policy infrastructure.
Microsoft is introducing dedicated Purview policy locations for supported non-Microsoft applications, including:
- Google Workspace
- Box
- Dropbox
- Salesforce
- ServiceNow
- AWS
- Cisco Webex
Who is affected?
Organizations using the Instances policy location to protect data in supported non-Microsoft applications.
If your organization isn’t using the Instances location, no action is required.
What should IT teams do?
Review your existing Purview DLP and auto-labeling policies.
Identify policies using the Instances location and determine which applications they apply to.
You’ll then need to migrate those policies to their corresponding dedicated application locations.
For example:
- Instances (Box) → Box
- Instances (Google Workspace) → Google Workspace
- Instances (Dropbox) → Dropbox
Before retiring legacy policies, test the new policies and validate that they continue to provide the expected data protection.
Microsoft Entra ID: Passkeys Become the Default
What’s changing?
Microsoft is continuing its move toward phishing-resistant authentication, with passkeys becoming the default authentication experience for Microsoft Entra beginning September 1, 2026.
At the same time, Microsoft-provided SMS and voice authentication are being retired.
Key dates:
- September 1, 2026: Passkey rollout begins.
- September 18, 2026: Review available telecom providers in the Microsoft Security Store.
- October 30, 2026: Customers that need to continue SMS or voice can select from available providers.
- February 1, 2027: Microsoft-provided SMS and voice authentication is retired.
Who is affected?
All Microsoft Entra tenants and users currently using Microsoft-provided SMS or voice authentication.
Users may begin seeing prompts to register a passkey during MFA sign-in.
Organizations that continue relying on Microsoft-provided SMS or voice without configuring a customer-managed telecom provider may experience sign-in disruptions after the retirement date.
What should IT teams do?
Start preparing users for the transition.
- Evaluate your authentication methods. Determine where SMS and voice authentication are still being used.
- Plan for passkey adoption. Communicate upcoming registration prompts to users and prepare help desk teams for questions.
- Configure a telecom provider if necessary. Organizations that need to continue using SMS or voice should configure a customer-managed provider before the February 1, 2027 retirement.
- Use the temporary opt-out if needed. Microsoft provides a temporary opt-out period from September 1, 2026 through February 1, 2027 for organizations that need additional time to transition.
For EDU and SLED environments with thousands of students, faculty, employees, contractors, and other users, authentication changes require more than a technical configuration. User communication and help desk preparation are just as important.
OneDrive Sync App Support Ends for Older Windows 10 Versions
What’s changing?
Microsoft is ending OneDrive sync app updates for devices running Windows 10 version 21H2 and earlier.
Support for those versions ends August 15, 2026.
Windows 10 version 22H2 will continue receiving OneDrive sync app feature updates, bug fixes, and security updates through October 10, 2028.
Who is affected?
Organizations with devices running Windows 10 version 21H2 or earlier.
Those devices may continue to access OneDrive, but they will no longer receive OneDrive sync app updates, bug fixes, or security updates.
What should IT teams do?
Identify devices running unsupported Windows versions.
Where possible:
- Upgrade affected devices to Windows 11.
- At minimum, upgrade to Windows 10 version 22H2.
- Communicate the change to users.
- Update help desk documentation.
- Remind users that OneDrive on the web remains available through supported browsers.
For school districts and government agencies managing large device fleets, this is a good opportunity to review endpoint lifecycle and patch management processes more broadly.
Exchange Online: Migrate Free/Busy, MailTips, and Calendar Sharing
What’s changing?
The retirement of EWS will affect more than custom applications.
Cross-tenant collaboration features—including Free/Busy, MailTips, and Calendar Sharing—currently rely on EWS and need to move to the Microsoft 365 Cross-Tenant Access Policy.
The new policy capabilities become available beginning September 2026.
EWS deprecation begins October 1, 2026.
Who is affected?
Your organization may be affected if your Microsoft 365 tenant shares Free/Busy information, calendars, or MailTips with other Microsoft 365 organizations through:
- Organization Relationships
- Availability Address Spaces
- Sharing Policies
Microsoft provides Exchange Online PowerShell commands that can help identify whether your tenant is using these configurations.
What should IT teams do?
- Review your existing cross-tenant sharing configuration.
- Use PowerShell to determine whether your organization is in scope, then:
- Review the Microsoft 365 Cross-Tenant Access Policy migration guidance.
- Configure the appropriate cross-tenant access policies.
- Validate the new configuration.
- Remove unused legacy configurations.
- Monitor the transition as Microsoft rolls out the change.
Microsoft notes that hybrid and on-premises scenarios are outside the scope of this change and should migrate to the Dedicated Hybrid App instead.
A temporary EWS extension is available while organizations complete their migration, but it should be viewed as a bridge—not a long-term solution.
Microsoft Entra ID: Replace MemberOf Rules by November 2026
What’s changing?
Microsoft is ending the public preview of the MemberOf rule operator in Microsoft Entra ID.
Organizations using MemberOf in:
- Dynamic membership groups
- Dynamic administrative units
- Entitlement Management auto-assignment policies
must replace those configurations by November 3, 2026.
Why does it matter?
MemberOf configurations can affect dynamic membership processing across a tenant and are not recommended for production use.
If no action is taken, configurations using the MemberOf operator will stop updating after the retirement date.
That could result in stale access and enforcement gaps.
For example:
- New users may not receive the correct Teams or SharePoint access.
- Removed users may retain access longer than intended.
- Conditional Access policies may not reflect current membership.
- Entitlement Management assignments may not update correctly.
- Group-based licensing may become outdated.
- Administrative unit membership may no longer accurately reflect your environment.
What should IT teams do?
Review your Entra environment and identify configurations using MemberOf.
For dynamic membership groups:
- Export affected groups.
- Identify rules containing MemberOf.
- Replace them with supported rule operators or convert groups to assigned membership.
- Validate membership after making changes.
For dynamic administrative units:
- Identify affected units using Microsoft Graph PowerShell.
- Replace MemberOf rules with supported operators or assigned membership.
- Validate membership and administrative scope.
For Entitlement Management:
- Identify affected auto-assignment policies.
- Replace MemberOf-based rules where possible.
- Plan an alternative assignment method where no equivalent exists.
- Validate access package assignments.
What EDU & SLED IT Teams Should Do Now
Microsoft 365 changes don’t happen in a vacuum.
A retirement that looks like a simple platform update can affect authentication, application integrations, data protection, collaboration, endpoint security, and access management across your organization.
For education and government IT teams, the challenge is often less about understanding what Microsoft is changing and more about finding the time and resources to determine what those changes mean for your environment.
Start with these five steps:
- Review your Microsoft 365 Message Center
Don’t wait for a user to report an issue. Review upcoming Microsoft changes regularly and identify updates that require action.
- Inventory applications and integrations
Pay particular attention to applications that interact with Exchange Online, Entra ID, Microsoft Graph, SharePoint, OneDrive, and other Microsoft 365 services.
- Review identity and Conditional Access
Authentication changes—including passkeys, MFA provider changes, and Conditional Access updates—can have organization-wide implications.
- Review your data protection policies
Make sure your DLP policies are using the Microsoft Purview capabilities and policy locations that will continue to be supported.
- Build migrations into your roadmap
Retirement dates have a way of arriving faster than expected. Give your team time to test, communicate, troubleshoot, and document changes before enforcement begins.
Microsoft 365 Security Is Powerful. Managing It Is the Hard Part.
Most EDU and SLED organizations already own powerful security capabilities through Microsoft 365, including Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview.
The challenge is putting those tools to work consistently—while keeping up with Microsoft’s constant changes and managing everything else on your IT team’s plate.
That’s where Forsyte can help.
Guardian 365 provides 24×7×365 managed security operations built around the Microsoft security ecosystem you already own. Our team helps organizations monitor, investigate, hunt for threats, respond to incidents, and continuously improve their security posture.
For education and government organizations, that means getting more from your Microsoft investment without having to build and staff a full security operation in-house.
We make security easy.
Ready to make security easy?
Find out where your organization stands. Our free security assessment gives you a clear picture of your current posture and a roadmap for what comes next.