Writing
Microsoft, VMware and identity deadlines, explained.
Cornerstone writing on the EOL waves, the platform shifts, and the identity work happening right now in the Microsoft project space.
Deadline: Sept 30 incident · PIR pending
Azure gateway outage: your VPN backup shared the failure
Microsoft says a subset of customers using gateway services in multiple regions had degraded or interrupted connectivity from 20:30 UTC September 30 to 02:15 UTC October 1. ExpressRoute Gateway and VPN Gateway were both on its impacted list, so a VPN failover for ExpressRoute may have shared one dependency with the primary. Microsoft reverted a change to a regional gateway management service; its Post Incident Review is still pending. A checklist for mapping shared failure domains.
Read the post →
Deadline: Opened Sept 25 · Mitigated, no fix date
AVD + FSLogix black screen after sign-in: KB5120998
Microsoft's known issue ties a black screen after sign-in, mostly on Azure Virtual Desktop hosts using FSLogix, to the August 2026 preview update KB5120998. Confirm the pattern, give users the explorer.exe workaround, apply the Known Issue Rollback Group Policy and restart, then watch for Resolved.
Read the post →
Deadline: Lock ≠ air gap ≠ tested restore
Immutable backup vs air gap: what it is and what to ask
Immutable backup locks a stored copy; an air gap disconnects it; neither proves you can restore. What Azure immutable vaults, AWS Backup Vault Lock and Veeam hardened repositories actually lock, and the questions to ask before you trust any of them.
Read the post →
Deadline: EOS Oct 12, 2027
SQL Server 2017 end of life: October 12, 2027 — your options
SQL Server 2017 leaves extended support October 12, 2027, and Microsoft's ESU page lists no 2017 offer yet. What end of support means, and the upgrade and Azure paths to plan a year out.
Read the post →
Deadline: Pro/Home: Oct 13, 2026
Windows 11 24H2 end of life: Oct 13 (Pro, Home)
Windows 11 version 24H2 stops getting updates October 13, 2026 on Home and Pro, but October 12, 2027 on Enterprise and Education. Check the edition on every device, then move Pro machines to 25H2.
Read the post →
Deadline: Comments due Nov 30, 2026
NIST SP 800-82 Rev. 4 draft: what changes for OT security
NIST's initial public draft of SP 800-82 Rev. 4 rebuilds its OT security guide around CSF 2.0. The six listed changes in plain language for manufacturers, and what to do before comments close.
Read the post →
Deadline: EOS Jan 11, 2027
Dynamics NAV 2017 end of support: January 11, 2027
Dynamics NAV 2017 leaves support January 11, 2027. Microsoft's upgrade path to Business Central runs through version 14 and a C/AL-to-AL conversion, and NAV 2018 follows in January 2028.
Read the post →
Deadline: In force: fully since June 30, 2024
Washington My Health My Data Act: Does It Apply?
Washington's My Health My Data Act has been fully in effect since June 2024. Who counts as a regulated entity or processor, what the Attorney General's own FAQ says about enforcement and private action, and what IT has to track if it applies to you.
Read the post →
Deadline: E5 = Entra ID P2, not ID Governance
Is Entra ID Governance included in E5? No, here's the gap
No. E5 includes Entra ID P2, which already covers PIM, access reviews and entitlement management. Entra ID Governance is a separate product. What P2 gives you, what Governance adds (Lifecycle Workflows, ML-assisted reviews, guest governance), and the ways to get it.
Read the post →
Deadline: Support ends no later than April 29, 2029
Backup Exec end of support: April 29, 2029, and your plan
Arctera's own Maintenance Documentation sets April 29, 2029 as the outer limit for Backup Exec support, and individual versions can lose maintenance sooner. What the document says about maintenance tiers, your old backup sets, and how to sequence a migration.
Read the post →
Deadline: AWS update, Sept 15, 2026
AWS can't restore some data: redundancy is not a backup
AWS says it cannot restore data hosted exclusively in its Bahrain Region or in one UAE Availability Zone: the damage exceeded what regional and multi-AZ design withstands. Its advice all along was to restore from remote backups in other Regions. Redundancy protects availability; a backup is a copy the same event cannot reach.
Read the post →
Deadline: HIPAA: backup Required, testing Addressable
Untested backups: what HIPAA and CIS expect you to prove
HIPAA's contingency plan standard requires a data backup plan and a disaster recovery plan; testing and revision is Addressable, with no interval set. CIS Controls v8 Safeguard 11.5 sets one: test restores quarterly, for a sample of assets, or fail the safeguard. What a real restore test looks like.
Read the post →
Deadline: Native Microsoft 365 Backup: $0.15/GB/month
Microsoft 365 backup: what Microsoft covers, and what you do
Microsoft runs a resilient service, and its own pages say what that protects and what stays with you. What Microsoft 365 Backup covers, how far back it restores, who can delete a backup, what it costs, and when a third-party tool is the better fit.
Read the post →
Deadline: Opened Sept 16 · Mitigated, no fix date
KB5124008 + Machine Identity Isolation: lost domain trust
KB5124008 makes Windows 11 honor previously configured Machine Identity Isolation settings, and Credential Guard devices in domains below Windows Server 2025 Domain Functional Level can lose their trust relationship. Find where the setting was turned on, disable it the same way, then repair the secure channel.
Read the post →
Deadline: Resolved Sept 14 · out-of-band KB per version
RDS can stop responding after the September 2026 update
Microsoft's September 2026 Windows security updates carried a known issue that could destabilize Remote Desktop Services: RDP dropping after several minutes, sign-in failures, or hangs at the configuration screen. Microsoft resolved it on September 14, 2026 with an out-of-band cumulative update — a different KB for each Windows version. Each version's September update also closes one of two privilege-escalation CVEs CISA lists as exploited, so install the fix rather than skip the month.
Read the post →
Deadline: Comments close Oct 5 / Oct 15
Two NIST drafts: multi-cloud boundaries, CSF AI prompts
Two NIST initial public drafts, neither binding. IR 8613 names the real multi-cloud difficulty as boundary definition — you can secure two clouds competently and still be unable to state where your system ends, which is what every attestation rests on. SP 1353 ships structured AI prompts for CSF 2.0 work, which matters less for the prompts than for the fact that NIST published them. Use AI to document what is true faster; never to decide what is true.
Read the post →
Deadline: Ports before January
Teams RTMP-In: open ports 50118 and 50119 now
Teams RTMP-In is consolidating onto *.rtmpingest.mcr.teams.cloud.microsoft with outbound TCP 50118/50119 by the end of 2026. Existing events keep working through 2026; newly created events may fail after December 31 — may, not will, and newly created, not all. The rollout has been paused since July and Microsoft has not said when it resumes. Two outbound ports, reversible, already required for additional streams today.
Read the post →
Deadline: Enterprise: early 2027
Edge Manifest V2: enterprise deprecation is early 2027
Edge began retiring Manifest V2 extensions for consumers in August 2026, aiming to finish by year end — and Microsoft's own blog states managed devices are not affected during that rollout. Enterprise deprecation follows in early 2027. Meanwhile the ExtensionManifestV2Availability policy page still says no timeline has been set and implies the override survives, while the Message Center says the policy is removed. 95% of top MV2 extensions already ship MV3; of the 58 still in real use, only 3 have no successor.
Read the post →
Deadline: Portable VCF by Oct 31, 2026
Azure VMware Solution: licence-included ends Oct 31
Microsoft stopped including a VCF licence with new Azure VMware Solution nodes on November 1, 2025. Existing licence-included deployments have to move to a customer-held portable VCF licence — pay-as-you-go by October 31, 2026, reserved instances by August 30, 2027. Nothing powers off on those dates; you simply stop being compliant, and you find out in a true-up. And if AVS was picked as a way around Broadcom, this is where that stops being true on paper.
Read the post →
Deadline: Enforcement Oct 5, 2026
Entra SSPR: unregistered contact info stops Oct 5
From October 5, 2026 Entra self-service password reset accepts only explicitly registered authentication methods — a synced mobilePhone or otherMails that the user never registered stops counting for verification. Prepopulation from your on-premises directory still works; it just no longer counts as coverage. Microsoft's own page also dates the registration campaign meant to precede enforcement to November 9, five weeks after it.
Read the post →
Deadline: Six items, two days
Everything Microsoft retires on September 30 and October 1
Six dated Microsoft items (a seventh, Entra Connect Sync, came off the list on September 29) land across two consecutive days at quarter-end, and no Microsoft page lists them together. Organized by what actually happens: ConfigMgr 2503 stops being patched; Project Online and Publisher stop being available; Entra ID Protection risk policies stop enforcing silently; the CSP uplift costs money. And the Azure Migrate classic appliance already passed its final recovery point in May. Two items in the cluster use opposite date encodings.
Read the post →
Deadline: Live since Jul 22
Copilot GCC: a setting that processes data outside FedRAMP
Since July 22, 2026 non-federal GCC tenants have a Microsoft 365 admin center setting that enables Anthropic models in Copilot. It is off by default, and Microsoft states plainly that when enabled these models process Customer Data outside its FedRAMP-authorized U.S. Government cloud. Scoping it to a security group limits who can invoke it, not where processing happens. Separately, Anthropic models with Data Retention sit outside your Microsoft DPA entirely — Anthropic acts as an independent processor, with retention up to two years on flagged content.
Read the post →
Deadline: Two surfaces now
Exchange auth certificate renewal now has a second step
The Exchange auth certificate used to live only on your Exchange servers. Since the shared service principal was permanently blocked on October 31, 2025, it also lives in a dedicated Entra hybrid application — and renewing on-premises does not update it there. Worse, two Microsoft pages collide: one says run the Hybrid Configuration Wizard after replacing the certificate, the other warns that doing so re-uploads it to the first-party service principal you were told to purge for CVE-2025-53786.
Read the post →
Deadline: GA now — plan the exit
Autopilot device association: what removal requires
Windows Autopilot device association is generally available, and it works by writing a tenant affinity marker into the device's UEFI firmware. The catch is at the other end of the lifecycle: Microsoft states that removing association from Intune is not supported, and that deleting the device from the Intune list does not clear the marker on an already associated device. Removal needs elevated PowerShell run on the device — and if you clear it before unenrolling, the MDM re-associates on next check-in.
Read the post →
Deadline: v29 — 2026 wave 2
Business Central 29 removes SOAP on Microsoft's own pages
Most coverage says Business Central 29 removes SOAP. Microsoft's dated commitment is narrower: it removes SOAP for Microsoft's own UI pages, and deletes the Feature Management key that currently re-enables them. The giveaway is Microsoft's own third migration option — replicate the pages in a per-tenant extension and publish those as SOAP. There is a separate, broader deprecation with no version and no date. One is a deadline; the other is a direction. And moving to OData on the same Microsoft page buys one release: version 30 (2027 wave 1) removes OData on Microsoft pages too.
Read the post →
Deadline: Publishing stops Sept
Dynamics 365 Release Planner retires by November 15
Three similarly-named things, only two of them retiring. Release plans stop being published to Microsoft Learn from September 2026 and Release Planner retires by November 15 — but release waves are a servicing cadence and are not going anywhere, so Business Central on-prem end-of-servicing dates are unaffected. The quiet sentence worth planning around: existing release plans remain available only 'until further notice', which is an intention rather than a commitment.
Read the post →
Deadline: Sept — month only
Entra custom controls stop accepting edits in September
Adding and editing Conditional Access custom controls stops being allowed in September 2026, with full retirement in early 2027. The trap is in Microsoft's own editing instructions: there is no in-place edit, so editing means deleting the control and creating a new one. Once creation is blocked, deleting one to change it is permanent. And per Microsoft's limitations, a custom control never satisfied a multifactor authentication claim in the first place.
Read the post →
Deadline: Read-only Sept 25
Microsoft Whiteboard: legacy boards deleted October 16
Whiteboards still in Microsoft's legacy Azure storage go read-only on September 25, 2026 and are permanently deleted on October 16 — Microsoft's words are 'permanently deleted and cannot be recovered'. September 25 is the date that actually constrains you, because that is when the migration route closes. Migration is user-triggered, so the boards least likely to migrate belong to the people least likely to open them. Microsoft Whiteboard itself is not retiring.
Read the post →
Deadline: Sep 30 — 25 days
Configuration Manager 2503 support ends September 30
ConfigMgr 2503 reaches end of servicing on September 30, 2026. Only three versions are supported today: 2503, 2509 and 2603 — and version 2409 quietly expired on June 6, 2026. Every Current Branch version gets exactly 18 months from its own release date, which is why these dates land on a Friday, a Wednesday and a Saturday rather than a Patch Tuesday. The reason it matters more than a normal lifecycle row: ConfigMgr is often the tool that patches everything else, so this is the control going unsupported, not the thing being controlled.
Read the post →
Deadline: Nov 3 — nothing errors
Entra dynamic groups: memberOf retires November 3
After November 3, 2026 dynamic membership groups, dynamic administrative units and entitlement management auto-assignment policies that use the memberOf operator stop updating and remain in their last known state. Microsoft names the consequences itself: outdated Teams and SharePoint access, Conditional Access targeting, group-based licensing and access package assignments. The Conditional Access one is the expensive one — a policy scoped to a frozen group silently stops covering new joiners while still showing as enabled. There is no replacement operator yet.
Read the post →
Deadline: Auto-enrolling now
Passkeys became the Entra ID default on September 1
Most coverage leads with the ending — Microsoft-provided SMS and voice authentication retires February 1, 2027 with, in Microsoft's words, no opt-out option. That is not what is happening in your tenant this month. Since September 1 users enabled for SMS or voice are being automatically enabled for passkeys and prompted to register one during an authentication they were already performing. The prompt reaches your users before it reaches your project plan, and blocking it moves the work from September to February rather than removing it.
Read the post →
Deadline: P2 only — check first
Entra ID Protection risk policies retire October 1, 2026
Microsoft retires the legacy user risk and sign-in risk policies inside Entra ID Protection on October 1, 2026. The first question is whether it is your deadline at all: Microsoft's license table puts risk policies at P2 only, and P1 ships with Microsoft 365 E3 and Business Premium while P2 comes with E5. If it is yours, the replacement is two separate Conditional Access policies — and the Conditional Access Administrator role explicitly cannot disable the legacy policy it replaces.
Read the post →
Deadline: Claim window: Sept 30
M365 outage, August 2026: what the SLA actually pays
Microsoft's August 31 incident ran into September under one ID and hit ten Microsoft 365 services — Defender XDR among them, so the tool you would use to tell an outage from an attack was inside the failure. Separately, Microsoft's Volume Licensing SLA pays a service credit when measured uptime falls short. It is worth one month's fee for the affected service, you must choose one Service Level when an incident trips two, and a suite license does not unlock a claim per service. The conservative filing deadline is September 30, 2026.
Read the post →
Deadline: Six platforms, one Tuesday
.NET 8 LTS ends November 10, 2026, and PowerShell with it
Six Microsoft platforms end support on November 10, 2026: .NET 8 LTS, .NET 9, PowerShell 7.4 LTS, PowerShell 7.5, and Windows 11 23H2 on Enterprise and IoT Enterprise. PowerShell dies with .NET because it inherits the runtime's lifecycle — the successors share an end date too. And Windows 11 carries three dates a year apart, separated only by edition.
Read the post →
Deadline: M365: Oct 1, files included
Microsoft Publisher retires October 1, 2026
Most end-of-support dates are a risk decision — the software keeps running and you carry the risk. This one is not. Microsoft 365 subscribers lose Publisher after October 1, 2026 and, in Microsoft's own words, can no longer open or edit their existing .pub files. The perpetual version has a different date and keeps working. And Microsoft's bulk-conversion script needs a licensed Publisher install to run, so it has to be finished before the app goes away.
Read the post →
Deadline: Six 10.0s, nothing to patch
Entra ID RCE: six CVSS 10.0 CVEs you cannot patch
Microsoft published six CVSS 10.0 cloud-service CVEs on August 20, 2026 — an Entra ID remote code execution flaw among them — and every record reads customerActionRequired: false. There is no KB number, no maintenance window, and nothing your scanner could ever have found. What a mid-market tenant actually controls here is identity configuration, not patch cadence.
Read the post →
Deadline: Three costs, one budget cycle
What a 2026 infrastructure refresh actually costs
A VMware exit is not one cost. Broadcom's licensing changes, hosts that are mostly memory in the middle of a shortage IDC expects to run through 2027, and a 5% Microsoft CSP uplift landing October 1 all hit the same budget. The asymmetry is the argument: hyperscalers signed long-term agreements capping their memory increases. A firm buying three hosts did not.
Read the post →
Deadline: Not law — policy direction
Washington's first data privacy report and the mid-market
Washington's Attorney General published the state's first Data Privacy Report on August 14: 209 breaches in 2025, more than eight million residents, over four in five exposing Social Security numbers. Four days later, independent research put 73% of ransomware victims in the $10M–$1B revenue band. Nothing here is law. Both are worth reading anyway.
Read the post →
Deadline: The plant floor sets the plan
Manufacturing VMware exit: the plant floor sets the plan
A manufacturing VMware exit is not gated by the hypervisor. It is gated by a cutover window measured against production schedules, machine-attached workstations pinned to OS versions by warranty, and segments that genuinely cannot reach the internet. Which systems move first, which move last, and why the historian usually decides.
Read the post →
Deadline: The field is the hard half
Microsoft 365 migration with a field-mobile workforce
The office half of a Microsoft 365 migration is the easy half. Re-authentication is the migration event nobody schedules — and the users who cannot complete it are the ones you cannot reach by walking to a desk. Shared site devices, crews that change between phases, and connectivity that is genuinely intermittent.
Read the post →
Deadline: Census before wave plan
Litigation hold blocks the mailbox migration you planned
A mailbox on hold does not migrate cleanly, and most plans discover this mid-cutover. The hold census belongs before the wave plan, not during it. Retention policy, retention label and hold are three different things routinely conflated — and the decision to release one belongs to the firm's counsel, never to IT.
Read the post →
Deadline: The calendar, not the tech
The close cycle sets your migration calendar
In a finance organization the close cycle sets the migration calendar. Month-end, quarter-end, year-end and audit fieldwork eliminate most of the year, and what is left is narrower than any project plan assumes. Plus the part nobody designs up front: administrative access during the period is an audit artifact, not a convenience.
Read the post →
Deadline: Allow list required Oct 10, 2026
EWS retirement: allow list required from October 10
Microsoft's Exchange Team says EWS deprecation started October 1, 2026. Starting October 10, an EWSAllowedAppIDs list is required wherever EWSEnabled = True in the worldwide cloud; Microsoft builds one on October 8-9 only for tenants it recorded on October 2, and list changes take 24 hours. Tenants still at Null are switched off later, each with a 7-day Message Center warning. Two similarly named controls still trip people up.
Read the post →
Deadline: EOS Jan 12, 2027
Windows Server 2016 End of Support: ESU or Modernize?
Windows Server 2016 leaves extended support January 12, 2027 — and the same date takes Hyper-V Server 2016, IIS 10, WSUS, Defender, Storage Server 2016 and .NET 4.6.2, while the day before takes the whole System Center 2016 family. Backup and monitoring expire before the servers they cover, which inverts the usual sequencing. ESU is quotable as of August 13.
Read the post →
Deadline: Seven items, one day
Everything Microsoft retires on October 13, 2026
Seven Microsoft lifecycle items end on October 13, 2026 — and every table says October 14, because the cells carry a timestamp on the morning after the last supported day. A triage list: what actually stops, what only changes phase, and two places Microsoft's own summary page contradicts itself.
Read the post →
Deadline: 26.x out of servicing Oct 13
Business Central on-prem: the servicing clock nobody reads
Business Central on-premises versions carry about eighteen months of servicing each — but waves land twice a year, so a version drops out roughly every six months. 25.x lapsed in April 2026, 26.x lapses October 13. Two lapses in one calendar year, neither with an end-of-life headline attached.
Read the post →
Deadline: The split, in writing
Co-managed IT: what it actually covers
Co-managed IT is sold as a philosophy and bought as a division of labour. What your team keeps, what a partner takes, who holds which escalation, whose tenant the tooling lives in, and how project work differs from steady state. Includes the failure mode nobody sells against — your own senior people ending up as the escalation tier for someone else's junior bench — and the cases where co-managed is the wrong answer.
Read the post →
Deadline: 2.6.84.0 + app auth by Apr 7, 2027
Entra Connect Sync deadline: April 7, 2027, not Sept 30
On September 29, 2026, Microsoft replaced its September 30 cutoff. Entra Connect Sync now needs version 2.6.84.0 or later and application-based authentication by April 7, 2027, or synchronization stops — password hash sync, joiner and leaver provisioning, all of it. The old minimum, 2.5.79.0, still reaches end of support on October 23, 2026. And the authentication change lands on a Tier-0 server.
Read the post →
Deadline: Retires Sep 30 · recovery point already gone
Azure Migrate classic appliance retires September 2026
Azure Migrate's classic replication appliance retires 30 September 2026 — but the final recovery point for existing replications was 31 May 2026, a date already behind us. Anyone still replicating through it is in a degraded state now, not in six weeks. What to move to, and what memory pricing is doing to the host refresh that usually rides along with a VMware exit.
Read the post →
Deadline: Renamed from Azure Stack HCI
Azure Local as a VMware exit: what it is, what it costs
Azure Local is the product Microsoft used to call Azure Stack HCI — the old docs URL redirects to the new one. What it actually is, how per-physical-core pricing compares to Broadcom’s 16-core-per-socket minimum, whether it needs a live Azure connection, and the cases where plain Hyper-V is the more honest answer.
Read the post →
Deadline: Per host, not per core
XCP-ng as a VMware exit: free hypervisor, priced platform
XCP-ng is a Type-1 Xen hypervisor that Vates describes as having no limits and no license. The money is in Xen Orchestra and the Vates VMS bundle around it — priced per host, per year, with no CPU or RAM limits, which inverts the density penalty Broadcom’s core minimum creates.
Read the post →
Deadline: GP retires Dec 31, 2029
Dynamics GP retires end of 2029: what actually migrates
Microsoft retires Dynamics GP at the end of 2029 — on the Modern Lifecycle Policy, so there is no extended-support phase behind it. Microsoft points GP at Business Central and ships a migration tool. What that tool does to your chart of accounts, the four things it does not bring, and the place Microsoft’s own documentation contradicts itself.
Read the post →
Deadline: Updated Sept 18 · KEV added Sept 16
CISA KEV, September 2026: patch, then assume compromise
The standing page for CISA's Known Exploited Vulnerabilities catalog in 2026, dated update by update. Catalog 2026.09.16 added Cisco Secure Email Gateway and Cisco ISE, both confirmed exploited by Cisco itself, plus an Acronis Backup plugin for cPanel and Plesk, and the vCenter flaw from August is now recorded as used in ransomware campaigns. The due dates bind federal civilian agencies, not you; what transfers is the sequencing: patch, then run forensic triage to find out whether you were already compromised.
Read the post →
Deadline: Project Online retires Sep 30, 2026
Project Server end of support: three paths
Project Server 2016 and 2019 ended support July 14, 2026 — and the destination most teams name first, Project Online, retires September 30, 2026. It has a shorter remaining life than the thing you are leaving. Three real paths, the desktop's own October 13 date, and why the on-premises option is a SharePoint Enterprise decision wearing a different name.
Read the post →
Deadline: EOS Jul 14, 2026 · ESUs to Jul 2029
SQL Server 2016 end of support: ESU or upgrade?
SQL Server 2016 left extended support on July 14, 2026. The free-ESU-on-Azure-VM route that worked for 2012 and 2014 explicitly does not apply to 2016, and ESUs are delivered through Azure Arc. What they cover, what they cost, and the four real paths.
Read the post →
Deadline: ScreenConnect added to KEV Sept 11
Your provider's RMM is Tier 0: 8 questions to ask
An incomplete patch put an RMM platform on CISA's KEV catalog on August 3 — a bypass of a bug that was already fixed, reached through the tool's own remote-control feature. Why remote management tooling belongs in Tier 0, why 'patched' is a state you can lose, and eight questions your IT provider should be able to answer from memory.
Read the post →
Deadline: Suspended Jul 13, 2026 · RFI closed Aug 14
CMMC 2.0 Level 2 audits suspended: what to do now
The Department of War suspended CMMC Phase 2 on July 13, 2026 — the Nov 10 C3PAO mandate is off and Phases 3–4 are paused. But DFARS 252.204-7012 and NIST 800-171 self-attestation still bind, and with third-party assessment gone, an inflated SPRS score is a bigger False Claims Act risk. What changed, what didn't, and what to do now.
Read the post →
Deadline: Renewal-audit ready
Cyber-insurance readiness for the mid-market (2026)
Cyber-insurance renewal quietly became a security-controls audit — underwriters now verify MFA, EDR, and backups instead of trusting the checkbox. Where the 'MFA everywhere' gap reprices renewals and denies claims, backed by Coalition's 2026 claims data (BEC/FTF 58%, 70% dual extortion), and how to close it as a scoped 90-day readiness project.
Read the post →
Deadline: Agentic ID: 90-day cutover
Intune's June 2026 releases: STIG audits, shadow-AI control, agentic remediation
Three June 2026 Intune shipments for regulated mid-market IT: a Windows 11 STIG SCAP audit baseline (GCC High + Advanced Analytics), native shadow-AI detect-and-block for local AI agents like OpenClaw, and a Vulnerability Remediation Agent now on its own Entra agentic identity. What's base Intune, what's an add-on, and what's still preview.
Read the post →
Deadline: Oct 12, 2027 (consumer only)
Windows 10 ESU extended to 2027 — but not for your fleet
Microsoft quietly extended the free consumer Windows 10 ESU to Oct 12, 2027 — but it excludes every domain-joined, Entra-joined, and Intune-managed device you own. The two ESU programs, the registered-vs-joined trap, and the commercial cost ($61 → $122 → $244/device).
Read the post →
Deadline: Took effect Jul 1, 2026
Microsoft 365 prices rose July 1, 2026 — what to do now
Microsoft's new commercial pricing took effect July 1, 2026 — E3 $36→$39, E5 $57→$60, Business Basic $6→$7, Frontline up 25–33%. The pre-increase lock-in has closed, but the renewal-boundary mechanic still sets what you pay, and it is the playbook for the next increase.
Read the post →
Deadline: Jul–Nov 2026 stack
IT layoffs vs. 2026 deadlines: who runs the work?
H1-2026 tech cuts collided with a stacked Microsoft EOL calendar. When a team shrinks, the SharePoint, Exchange, and CMMC deadlines don't move — how a senior bench fills the gap without touching headcount.
Read the post →
Deadline: Aug 2026 SU kills OWA Light
Exchange Server SE: what modern servicing commits you to
You're on Exchange Server SE — now what? Single-version modern servicing, mandatory CU currency, the cloud dependency for on-prem servers, Server Core, and the coming product-key requirement. The August 2026 security update permanently disables OWA Light — and the KB never says so.
Read the post →
Deadline: SE CU2, date unannounced
Exchange Server Subscription Edition: CU2 coexistence trap
Exchange 2016/2019 are out of support; the paid ESU bridge ends Oct 2026. SE CU2 will block coexistence with legacy Exchange — closing the last clean migration window. The senior operator's runbook.
Read the post →
Deadline: Governance: 90-day playbook
Copilot governance one year on: the 12,000-permission reckoning
One year after the oversharing warning, mid-market Copilot tenants are leaking HR, finance, and legal docs. The 90-day playbook using Purview DSPM, SharePoint Advanced Management, and Restricted SharePoint Search.
Read the post →
Deadline: RC4 phase knob removed Jul 2026
Kerberos RC4 April 2026 enforcement: mid-market triage runbook
Microsoft's April 14 patch flipped DCs to AES-SHA1-only and broke RC4 service-account logins. The 3-hour triage runbook, and what the July 2026 updates actually remove.
Read the post →
Deadline: Period 2 is an enrollment gate
Exchange ESU Period 1 expired — your real deadline
The paid Exchange ESU bridge is nearly spent: Period 1 expired April 14, 2026 and Period 2 ends October 2026 (final). Only Period 2 enrollees receive the May–October 2026 updates — management-only hybrid servers included. The real deadline, four exit paths, and hour ranges for 50–1,500 seats.
Read the post →
AD functional level on Windows Server 2019/2022: not stuck at 2016
Microsoft skipped Server 2019 and 2022 functional levels. Server 2016 IS the maximum for any 2019/2022 forest. What Server 2025 (behavior version 10) actually adds.
Read the post →
Deadline: Identity-substrate
AD Tier-0 in 90 days: the mid-market edition
Microsoft's enterprise Tier-0 guidance is overkill for 100–500-user shops. The four controls and 12-week plan that close 80% of the gap at under 25% of the cost.
Read the post →
Deadline: M&A integration
M&A tenant merge in 60 days: the reference playbook
A worked reference scenario for folding a subsidiary tenant into a parent: two M365 tenants, one identity model, 60 days from legal close. Power Platform sprawl, externally shared apps, Teams chat fidelity, OneDrive personal data.
Read the post →
Deadline: Phase 2 suspended Jul 2026
CMMC L2 pre-assessment: what $15K buys you
A fixed-fee $15K pre-assessment for a 100–300-user GovCon shop — SSP draft, POA&M draft, GCC High eligibility, NIST 800-171 gap register, third-party app compatibility, two weeks.
Read the post →
Deadline: Renewal-driven
VMware to Azure vs Hyper-V: 500-VM decision guide
Six dimensions that decide whether a 500-VM mid-market VMware exit lands in Azure IaaS or Hyper-V on-prem. Two modelled reference estates and a decision matrix.
Read the post →
Deadline: EOL passed + 4 exploited CVEs
SharePoint 2016 & 2019 EOL July 14, 2026: three paths
SharePoint 2016 and 2019 hit end of support July 14, 2026 with no ESU at any price. Four actively-exploited flaws have hit the stack since, the newest (CVE-2026-65660) fixed by an August 11 security update Microsoft shipped after end of support. Project Server and SQL Server 2016 died the same day. SPO migration, Subscription Edition, or selective hybrid, with cutover math for 50/200/500 users.
Read the post →
Deadline: Pre-rollout
Is Microsoft Copilot HIPAA compliant? Read the BAA
Microsoft's BAA covers the platform, not your tenant configuration. The four pre-deployment fixes that keep Copilot on the right side of HIPAA.
Read the post →
Deadline: Renewal-driven
After Broadcom: 250-VM Hyper-V migration in 90 days
A worked reference scenario for a 250-VM mid-market VMware exit to Hyper-V: the four phases, the cost model, and what sends an estate to Azure instead.
Read the post →
Deadline: Jan 12, 2027 (Server 2016)
Windows Server 2019 EOS: real upgrade options for 2026
Windows Server 2019 is out of mainstream support and Server 2016 ends January 12, 2027. The real upgrade paths — in-place to Server 2025, rehost, or Azure — and the AD functional-level facts most teams get wrong.
Read the post →
Deadline: SE CU2, date unannounced
Exchange Server 2019 EOL: your real migration deadline
Exchange 2016/2019 lost support Oct 14, 2025; the paid ESU bridge ends Oct 2026. The four migration paths and the deadline that actually bites: SE CU2.
Read the post →
Deadline: Renewal-driven
VMware after Broadcom: your real exit options
vSphere → Hyper-V vs Nutanix vs Scale Computing vs Azure Local vs Proxmox. When each lands.
Read the post →
Deadline: Pre-rollout
Copilot readiness: the 12,000-permission problem
Why oversharing becomes a data-loss event when Copilot turns on, and how to fix it before you flip the switch.
Read the post →
Deadline: Phase 2 suspended Jul 2026
GCC High before CMMC Phase 2
The Nov 10, 2026 C3PAO mandate was suspended in July 2026 — what still binds, realistic GCC High timelines, common mistakes.
Read the post →
Tenant-to-tenant M365 migration: a playbook
The M&A and divestiture story, what tools fit when, and how to budget realistically.
Read the post →
Stay in the loop
Follow Pro IT NW on LinkedIn for new posts.
No newsletter, no signup form — LinkedIn notifications when we publish, or subscribe to the RSS feed.