From the Team
As summer starts its slow fade and calendars begin filling up again, we thought it was the perfect time to pause for a quick update from around the team. We've packed this edition with highlights, helpful tips, and a few things that might save you a support ticket or two.
Before pumpkin spice takes over every coffee shop in America, take a few minutes to catch up on what's new, what's changing, and what we're keeping an eye on.
LEARNING WEBINAR
CSPM: Session 6 Available
We’ve made it to part 6 of our Demystifying CSPM series! We know you were deeply concerned that we might run out of acronyms, but don’t worry, we have plenty left to throw at you.
In this session, we bravely tackle the age-old question, “is my cloud secure, or am I just really good at ignoring alerts?” Dive into the thrilling world of posture management where CSPM, SIEM, XDR and SOAR all try to play nice together, sometimes with actual automation, and sometimes with just a lot of notifications.
So, grab your popcorn (or your third cup of coffee), click play, and prepare to be dazzled by the only video series that makes cloud security posture management almost entertaining… almost. 😁
MICROSOFT UPDATE
SMS MFA Is Entering Its Fax Machine Era
Remember when text messages were the coolest thing on your phone? (Right along with flip phones, AIM away messages, and arguing about whether BlackBerry was the future.) Microsoft does too, and unfortunately, so do cybercriminals.
Microsoft has announced that SMS and voice-based authentication are headed for retirement with a full sendoff scheduled for February 1, 2027. In their place, Microsoft is putting passkeys front and center as the new standard for signing in securely.
Why the big change? Because while SMS-based MFA has been better than using passwords along, it’s increasingly become the digital equivalent of locking your front door while leaving the garage wide open. Between phishing attacks, SIM-swapping scams, and other tricks bad actors have picked up along the way, text messages just aren’t the security powerhouse they once were.
The good news is there is plenty of runway before the change becomes mandatory.
Identify employees still relying on SMS or voice MFA
Begin enabling passkeys where appropriate
Let employees know what’s coming before Microsoft does
Avoid the future “Why can’t I log in?!” help desk tickets
Microsoft’s message is clear: the future of authentication isn’t another six-digit text code. It’s phishing-resistant sign-ins that are easier for employees and harder for criminals.

Or put another way… Passwords are on life support. SMS is heading into retirement. Passkeys are the new kid on the block… and they’re already valedictorian.
Read more at Microsoft’s security blog: Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
ARTIFICIAL INTELLIGENCE
AI Readiness is Becoming a Security Conversation
Remember when our AI conversations were all about writing emails faster, summarizing meetings, and generating images of cats solving global problems?

As AI adoption accelerates, the conversation is quickly shifting from “What can AI do for me?” to “What exactly can AI see?" and “Should it be allowed to see that?”
The reality is that AI is only as smart as the data it’s given access to. Unfortunately, many of us have spent years accumulating files, permissions, shared folders, and forgotten SharePoint sites with all the organizational discipline of a garage packed after three decades of “I’ll deal with it later.”
AI doesn’t know the difference between an approved business document and the spreadsheet Brad uploaded in 2018 called Final_final_reallyFinal_v7.xlsx.
That is why security and data governance have become the new VIPs of every successful AI deployment. Before turning AI loose across your organization, it’s worth asking a few important questions:
Do we know where our sensitive data lives?
Are permissions still aligned to job responsibilities?
Is data properly classified and protected?
Are we prepared for AI to surface information that has technically been accessible all along?
The good news is that you don’t need to put your AI journey on pause until everything is perfect. But successful organizations are realizing that AI readiness isn’t just a technology project anymore, but rather it’s a security, governance, and business-process conversation.
Remember, AI doesn’t create data governance problems. It simply introduces them to management faster than ever before.
MICROSOFT UPDATE
Farewell Old Friend: EWS Retires October 1
Some technologies are cutting-edge. Some are modern. And some are Exchange Web Services (EWS). If you’ve been around long enough in the Microsoft ecosystem, EWS was that trusty old API that enabled all your other on-prem applications to play nicely with Exchange.
Sadly, after years of faithful services, we will be officially saying goodbye to EWS on October 1, 2026. The interesting thing about EWS is that most of us don’t intentionally use it anymore, but instead, we discover it unexpectedly still being used by legacy applications, third-party software integrations, automation workflows, and custom scripts that have been running longer than your last two computers.
ProTip - keep an eye on those scheduling pads outside every conference room, public space, and that really ambitious coworker trying to maximize everyone else efficiency who just got their own office…

Microsoft’s recommendation is to migrate to Microsoft Graph, which has become the strategic platform for Microsoft 365 integrations. While most people won’t notice a thing, you may want to take a closer look so that those “quietly running” systems that are often forgotten don’t become really noisy this fall.
More details at Exchange Online EWS, Your Time is Up.
SECURITY
Microsoft is Putting Security on a Purview Diet
For years, Microsoft’s security portfolio has felt a bit like a home improvement project that started with one toolbox and somehow ended up filling the entire garage. Defender protected some things, Purview protected other things, and we all occasionally needed a map to remember which portal we were supposed to be using.
Microsoft appears to be cleaning house… again (and not the first “again” in this sense).
As part of a broader effort to simplify data security and governance, Microsoft has announced that file-based Data Loss Prevention (DLP) currently in Defender for Cloud Apps will be moved into Purview. The message is becoming increasingly clear: Defender is focused on finding threats while Purview is becoming the home for data protection, classification, governance, and compliance.

“Why does this matter” you may ask? Because AI has a remarkable ability to shine a spotlight on data that we forgot existed. As companies accelerate Copilot and AI adoption, understanding where sensitive data lives, who has access to it, and how it’s protected is becoming just as important as protecting endpoint and identities.
If Defender is the security guard watching the doors, Purview is the librarian who knows exactly what’s on every shelf, who checked it out, and whether they should have access to it in the first place.
Details on preparing for this change can be found at Migrate File Policies to Microsoft Purview.
Have you scheduled you monthly checkpoint?
Our monthly checkpoints are your all-access pass to asking all the cloud questions you may have. Whether that is bouncing new ideas off of, looking for guidance on specific solutions, learning more about upcoming capabilities, diving deeper into a technical issue, or simply just being your monthly emotional support human. If you don’t have a monthly team checkpoint already scheduled, don’t be shy, drop us a message and let’s get one scheduled!
Until next month,
The Improving CSP Team

