[m365weekly] #216

M365 Newsletter title logo M365 Weekly Newsletter

Issue #216


☁️What’s on my mind

Doing nothing used to be free. Microsoft just patched that loophole. Now every expired subscription is a potential surprise invoice.

Microsoft is introducing EST – Extended Service Term.

A quick recap of what’s coming for Microsoft CSP partners and practically all Microsoft 365 business users on May 4.

What is EST? Microsoft is removing the old free 30-day grace period on May 4 this year. When a subscription expires, and auto-renew is off, it will move into a paid Extended Service Term at the monthly rate plus a 3 percent uplift or higher if no monthly SKU exists.

How did it work before? Previously, disabling auto-renew triggered a free grace period. Customers kept using the service while budgets or approvals were sorted out. That buffer no longer exists after May 4.

What changes? At the end of the term, you will have to pick one of three actions

  1. Renew.
  2. Cancel. Access ends immediately at expiration.
  3. Move to EST.

If you do nothing, the subscription defaults to EST.
Cancel really means the service stops. Mailbox stops working, Outlook stops receiving new emails, no OneDrive access … the whole thing.

So why should you care? Microsoft is done with accidental (or intentional) free usage. They want clean, predictable billing. For you, this means paying closer attention to renewals and making sure you don’t end up on a paid EST you didn’t ask for.

What to tell your customers if you’re Microsoft’s reseller?
Explain that doing nothing now costs money.
Tell them the three options and what each one means.
And remind them that canceling means the service stops immediately at term end.

Have a nice rest of the week,
Matic

☁️Productivity & Modern Workplace

What is Markdown and how it works with Microsoft Word. Markdown lets you format text using simple symbols like ** for bold or # for headings, offering a distraction-free writing experience. It’s widely used by developers, writers, and AI systems due to its readability and flexibility. While not a replacement for Word’s advanced features, it’s ideal for drafting.

The Excel Gantt Chart That Replaces Your Project Management Tool. You can create a modern, automated, and visually appealing Gantt chart in Excel using just three inputs: start date, duration, and progress. This setup updates dynamically to reflect changes in dates or task status, highlights weekends and current dates, and visually tracks progress without additional software. VIDEO

How to Block AI Assistants in Microsoft Teams Meetings. Microsoft Teams will soon introduce built-in detection for third-party AI meeting assistant bots. These bots will be flagged as “Unverified” in the meeting lobby, allowing organizers to admit, deny, or remove them. A new meeting policy will also give admins control over bot approvals.

[FEATURED STORY] ZT4AI: Taming wild AI before it bites back

Source: New tools and guidance: Announcing Zero Trust for AI

The big picture. Microsoft is extending its Zero Trust framework to AI with a new “Zero Trust for AI” (ZT4AI) approach that applies core Zero Trust principles – verify explicitly, least privilege, and assume breach – to the full AI lifecycle, from data and model training through deployment and agentic behavior. The company is rolling out an updated Zero Trust Workshop with a dedicated AI pillar (now covering 700 controls across 33 functional swim lanes), expanded Zero Trust Assessment capabilities for Data and Networking, a new Zero Trust reference architecture for AI, and accompanying patterns and practices for common AI‑security challenges.

Why is it important? AI introduces new trust boundaries between users and agents, models and data, and humans and automated decisions, creating “double agent” risks if agents are overprivileged, manipulated, or misaligned. Microsoft’s ZT4AI gives security teams a structured path, from strategy and assessment to implementation, so organizations can adopt AI at speed while automatically testing and enforcing controls aligned with standards like NIST and CIS, and preparing for an AI‑specific Assessment pillar coming in summer 2026.


☁️Copilot & AI

Why AI Doesn’t Give the Same Answer Twice (And Why That’s Not a Bug). AI systems generate responses based on probabilities, not fixed rules. This means small prompt changes can lead to varied outputs. Treat AI as a knowledgeable collaborator, not a source of absolute truth. Clear, specific instructions guide better results. Always review outputs; AI excels at assisting, not replacing critical thinking. Understanding this mindset shift improves how you use AI effectively.

Copilot Cowork Walkthrough. Copilot Co-Work is a cloud-based Microsoft 365 agent designed for complex, long-running tasks across multiple systems. It leverages Work IQ and integrates with tools like SharePoint, Teams, and Dynamics 365. It securely processes tasks in a sandbox, creates outputs in OneDrive, and supports interactive, multi-step workflows with reasoning models for efficient problem-solving. VIDEO


☁️Sysadmin Stuff

Entra Change Tracker. A community-built Entra change tracker simplifies staying updated on Microsoft updates using RSS feeds and a traffic-light urgency system. It runs entirely on free Cloudflare services, requiring no servers or maintenance. Updates include a personalised tenant profile for tailored alerts and an AADSTS error reference tool. Both tools are free, lightweight, and privacy-focused.

Create Email Signatures for Shared Mailboxes in Microsoft 365. AI operates probabilistically, generating responses based on likelihood rather than fixed rules. This explains why answers can vary, even to identical prompts. Clear, detailed instructions improve consistency by narrowing possibilities. While AI excels at drafting and ideation, it isn’t a source of absolute truth.

Microsoft Is Killing the Free Grace Period. Microsoft is ending the free 30-day grace period for expired CSP subscriptions on May 4, 2026. Instead, the new Extended Service Terms (EST) will charge subscriptions monthly, with a 3% or 23% price increase depending on the product. You’ll need to explicitly cancel subscriptions or risk automatic EST enrollment, potentially leading to surprise costs. Review workflows and inform clients now to avoid disruptions.


☁️Security & Data Governance

When OAuth Redirects Become a Phishing Tool. Attackers are abusing OAuth redirection in platforms like Microsoft Entra ID to deliver phishing pages or malware. They manipulate OAuth parameters to redirect users to malicious sites, exploiting trust in legitimate login flows. You can mitigate risks by blocking outbound B2B collaboration by default, allowing only trusted tenants, and analyzing sign-in logs using tools like Microsoft Sentinel or Defender.

How to Prevent Calendar Phishing Attacks in Microsoft 365. Calendar phishing attacks in Microsoft 365 exploit auto-added meeting invites to deliver malicious links. These events bypass traditional email defenses, persisting even if deleted from the inbox. Mitigation requires layered defenses: configure mail flow rules, enable Safe Links for real-time link scanning, train users to identify suspicious invites, and use Defender tools to remediate persistent calendar events.

File Level Archiving in SharePoint Online. Microsoft 365 Archive now supports file-level archiving in public preview, letting you archive specific files in SharePoint without impacting the site. Archived files retain metadata, permissions, and version history but move to a cheaper $0.05/GB/month storage tier. Reactivation is free, and archived files are excluded from Microsoft 365 Copilot responses. Admins can enable this feature via PowerShell.


☁️Noteworthy (long)reads

Evangelists, Marketers, and the People Who Explain Things for a Living. Technology evangelists, product marketers, and marketers each play distinct roles in making ideas resonate. Evangelists spark trust through storytelling and technical depth. Product marketers craft strategies to clarify why something matters. Marketers amplify that message to reach the right audience. When aligned, they create a powerful synergy. Misalignment leads to inefficiency.

Why Running Your MSP on “Hard Mode” Is Slowly Killing It. If your MSP feels exhausting to grow, the issue might be misalignment with your strengths, values, or goals—not your tools or tactics. Many MSPs unknowingly build businesses that clash with their personality and priorities, leading to burnout. Redesign your MSP to fit you. Focus on work that energizes you, align your model with your vision, and growth will feel natural.


DATES TO KEEP IN MIND

March 1, 2026 Retirement of Basic Authentication for Client Submission in Exchange Online (SMTP AUTH) – changed timeline- source.

May 4, 2026 – Microsoft is discontinuing the grace period for CSP subscriptions – source.

June 1, 2026 – Microsoft is retiring standalone SharePoint Online and OneDrive subscriptions – source.

September 30, 2026 – Project Online will retire – source.

October 2026Retirement of Microsoft Publisher app, which has been a part of the Office Suite for years.

October 13, 2026End of Support for Office LTSC 2021source.


☁️On a Less Serious Note


☁️ We value your feedback!

How much are you enjoying this issue? Please give us your feedback so we can improve.

If you have any suggestions, just reply and leave us your message.


☁️ Last but not least …

Here are a few things you can do if you enjoyed reading this newsletter:

Did someone forward this email? Sign up for the weekly newsletter here.