Blog Image - Msft Updates Sept 2026
September 22, 2026

Microsoft 365 Updates and Retirements: What EDU & SLED IT Teams Need to Know This September

Share this post
Author

Microsoft 365 continues to evolve — and for education and state and local government (SLED) IT teams, this month’s changes touch everything from browser security to calendar integrations to how your security team sees Data Loss Prevention (DLP) alerts.

From the retirement of legacy Microsoft Edge protections to changes coming to Microsoft Defender for Cloud Apps, Microsoft Defender for Endpoint, Microsoft Teams, Microsoft Defender XDR, and Project Online, several updates require IT teams to review configurations, identify affected users and devices, and plan changes before deadlines arrive.

For organizations already balancing cybersecurity, infrastructure, compliance, and day-to-day IT operations, keeping up with Microsoft 365 changes can be a challenge.

We’ve pulled together the updates that matter most and what EDU and SLED IT teams should do next.

The bottom line: Don’t wait for a Microsoft retirement date to become an outage. Review your environment now, identify what is affected, and build the necessary changes into your IT and security roadmap.


1. Microsoft Edge: Windows Information Protection and Application Guard Are Being Retired

What’s changing?

Microsoft is retiring support for Windows Information Protection (WIP) and Microsoft Defender Application Guard (MDAG) in Microsoft Edge. Both capabilities have already been deprecated in Windows and are no longer available in Windows 11, version 24H2.

The rollout begins worldwide in late September 2026 and is expected to complete the same month. Once it does, WIP and MDAG will no longer function in Microsoft Edge 154 and later versions.

For WIP scenarios, Microsoft recommends transitioning to Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention (DLP), Endpoint DLP, and Intune app protection policies. For MDAG scenarios, Microsoft recommends the built-in security capabilities in Microsoft Edge along with other supported isolation solutions.

Who is affected?

Organizations that have configured WIP or MDAG for Microsoft Edge on Windows 10 devices. Both features are off by default and require administrators to enable them, so organizations that have never turned them on are not affected — and Windows 11, version 24H2 devices are not expected to be affected either, since these capabilities have already been removed from that platform.

What should IT teams do?

  • Review current Microsoft Edge and Windows security configurations to determine whether WIP or MDAG is still in use.
  • If using WIP, plan migration to Microsoft Purview Information Protection, Purview DLP, Endpoint DLP, and/or Intune app protection policies where appropriate.
  • If using MDAG, evaluate supported Microsoft Edge security capabilities and alternative isolation technologies that meet your requirements.
  • Complete migration activities before rollout finishes in late September 2026, and contact Microsoft Support or your account team if more time is needed.

Microsoft resources

Announcing the Sunset of Windows Information Protection (WIP) — Windows IT Pro Blog

Microsoft Edge Support for Microsoft Defender Application Guard | Microsoft Learn

Get Started with Endpoint Data Loss Prevention | Microsoft Learn


2. Microsoft Defender for Cloud Apps: Cloud Application Administrator Role Loses App Governance Access

What’s changing?

Microsoft Defender for Cloud Apps is updating which Microsoft Entra roles grant access to App Governance when Unified Role-Based Access Control (URBAC) is enabled. Support for the Cloud Application Administrator role is being retired for App Governance access, aligning it with the standard supported role set used across Microsoft Defender services.

Retirement begins worldwide in late September 2026, with enforcement taking effect on September 26, 2026.

Who is affected?

Organizations that use App Governance in Microsoft Defender for Cloud Apps where administrators access it using only the Cloud Application Administrator role. After September 26, those administrators will lose App Governance access when URBAC is enabled. No end-user experience changes are expected.

What should IT teams do?

  • Review administrator role assignments by September 25, 2026.
  • Assign a supported role to any administrator who needs App Governance access: Security Administrator, Compliance Administrator, Compliance Data Administrator, Security Operator, Security Reader, Application Administrator, or Global Reader.
  • Assign each administrator the minimum role required for their responsibilities.


3. Microsoft Teams and Google Calendar Sync Is Being Retired

What’s changing?

Microsoft is retiring calendar syncing between Microsoft Teams and Google Workspace, available today through the Admin app in Teams. Microsoft is instead focusing investment on supported integrations such as the Microsoft Teams Meeting add-on for Google Workspace. Retirement is scheduled for October 2026, and affected customers began receiving notifications in August 2026.

Who is affected?

Organizations currently using calendar syncing between Microsoft Teams and Google Workspace. After retirement, previously matched and configured calendars will stop syncing, and administrators will no longer have access to calendar sync setup in the Admin app in Teams.

What should IT teams do?

  • Notify affected users that calendar synchronization will stop in October 2026.
  • Retrieve and retain any account matching information needed from the Admin app in Teams before the retirement date.
  • For users who need to schedule Teams meetings from Google Calendar, recommend the Microsoft Teams Meeting add-on for Google Workspace.

Microsoft resources

Microsoft Teams Meeting Add-on for Google Workspace

Set Up Calendar Syncing Between Google Workspace and Microsoft Teams | Microsoft Learn


4. Microsoft Defender for Endpoint: Migrate Legacy MMA Devices by February 2027

What’s changing?

Microsoft Defender for Endpoint protection delivered through the Microsoft Monitoring Agent (MMA) and Simple Certificate Enrollment Protocol (SCEP) on legacy Windows operating systems is being retired. Support for MMA-based protection on Windows 7 and Windows Server 2008 R2, 2012 R2, and 2016 ends on February 26, 2027. Affected devices must migrate to the current Defender agent before that date to maintain protection.

For eligible devices, the Defender deployment tool can simplify migration, and existing device records and timelines are preserved. Microsoft is also developing a replacement solution for Windows 8.1 devices, with additional guidance to follow.

Who is affected?

Organizations with devices running Windows 7, Windows Server 2008 R2, Windows Server 2012 R2, or Windows Server 2016 that use Defender for Endpoint through MMA. Devices not migrated before February 26, 2027 may no longer receive expected Defender functionality.

What should IT teams do?

  • Identify devices in your environment using MMA-based Defender for Endpoint protection.
  • Review migration guidance and device eligibility requirements.
  • Use the Defender deployment tool to migrate eligible devices to the current Defender agent.
  • Plan and schedule maintenance windows for affected devices, and review your strategy for Windows 8.1 devices ahead of future guidance.

Microsoft resources

Deploy Microsoft Defender Endpoint Security Using the Defender Deployment Tool | Microsoft Learn

Updating MMA on Windows Devices for Microsoft Defender for Endpoint | Microsoft Learn


5. Microsoft Defender XDR: DLP Alerts Move to Behaviors by Default

What’s changing?

Microsoft Defender XDR is introducing a new built-in alert tuning rule that sets Microsoft Purview DLP alerts as behaviors rather than standard alerts. This is designed to reduce alert volume in the Defender XDR incident queue while preserving DLP investigation data in Advanced Hunting and the Microsoft Purview portal. The rule is available for review today and will be enabled by default beginning October 12, 2026.

Who is affected?

Security administrators and analysts who use Microsoft Defender XDR alongside Microsoft Purview DLP. Once enabled, DLP alerts will no longer appear in the Defender XDR incident queue by default, though the underlying signals remain available through the BehaviorInfo and BehaviorEntities tables in Advanced Hunting and in the Purview portal. Organizations that pull DLP alerts programmatically through Graph Alerts V2 should note that data will move to the Microsoft Graph security runHuntingQuery API instead.

What should IT teams do?

  • No action is required if the new default experience is acceptable.
  • If DLP alerts should continue appearing in the Defender XDR incident queue, disable the rule before October 12, 2026 (or any time after) via Settings > Microsoft Defender XDR > Alert tuning, then locate and disable “Set-As-Behavior – Data Loss Prevention (DLP) Alerts.”
  • Evaluate downstream integrations, automation, reporting, and alert triage workflows that depend on DLP alerts appearing in the incident queue.


6. Project Online Essentials Reaches End of Life on October 1, 2026

What’s changing?

Project Online Essentials, which has not been available for purchase since October 1, 2025, reaches end of life on October 1, 2026. It currently provides licensing rights for Project Online and Project Server through Client Access Licenses (CALs). Project and Planner Plan 1 and Plan 3 provide broader capabilities, including Planner Premium experiences, while continuing to provide applicable licensing rights for supported Project scenarios.

Who is affected?

Organizations with users currently assigned Project Online Essentials licenses. After October 1, 2026, those users will lose access through that license and will need a supported replacement to retain Planner Premium capabilities or applicable Project Server access rights.

What should IT teams do?

  • Review users currently assigned Project Online Essentials licenses.
  • Determine whether those users need Planner Premium capabilities, Project Server access rights, or both.
  • Assign Project and Planner Plan 1 or Plan 3 for users who need Planner Premium capabilities or Project Server CALs; acquire the appropriate Project Server CALs for users who need only Project Server Subscription Edition access.
  • Notify affected project managers, resource managers, and Project Server users about the retirement and any licensing changes.


What EDU & SLED IT Teams Should Do Now

Microsoft 365 changes don’t happen in a vacuum. A retirement that looks like a simple platform update can affect browser security, identity and access, collaboration, endpoint protection, and project management across your organization.

For education and government IT teams, the challenge is often less about understanding what Microsoft is changing and more about finding the time and resources to determine what those changes mean for your environment.

Start with these steps:

  • Review your Microsoft 365 Message Center. Don’t wait for a user to report an issue — review upcoming changes regularly and identify what requires action.
  • Inventory devices and configurations. Pay particular attention to Windows 10 devices, legacy Defender for Endpoint agents, and Conditional Access or App Governance role assignments.
  • Review collaboration dependencies. Identify any Teams/Google Workspace calendar sync configurations and Project Online Essentials licenses that need a replacement.
  • Review your security operations workflows. Confirm whether the DLP alert tuning change affects your incident response and reporting processes.
  • Build migrations into your roadmap. Retirement dates have a way of arriving faster than expected. Give your team time to test, communicate, and document changes before enforcement begins.


Microsoft 365 Security Is Powerful. Managing It Is the Hard Part.

Most EDU and SLED organizations already own powerful security capabilities through Microsoft 365, including Microsoft Defender, Microsoft Entra ID, and Microsoft Purview. The challenge is putting those tools to work consistently — while keeping up with Microsoft’s constant changes and managing everything else on your IT team’s plate.

That’s where Forsyte can help.

Guardian 365 provides 24×7×365 managed security operations built around the Microsoft security ecosystem you already own. Our team helps organizations monitor, investigate, hunt for threats, respond to incidents, and continuously improve their security posture.

For education and government organizations, that means getting more from your Microsoft investment without having to build and staff a full security operation in-house.

We make security easy.

Ready to make security easy?

Find out where your organization stands. Our free security assessment gives you a clear picture of your current posture and a roadmap for what comes next.