Microsoft 365 Is Changing Again. Which September Changes Actually Matter?

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
Microsoft 365 changes are easier to manage when businesses separate urgent version and security work from changes that only affect particular tenants or legacy features.
Microsoft 365 changes constantly. Most changes are useful. Some are minor. A few can cause real problems if nobody notices them.
That creates a practical problem for small and medium-sized businesses. A change notice may describe a genuine deadline, a future direction, a tenant-specific feature or a legacy configuration that your organisation does not use at all.
For September and October 2026, the useful question is not “What are all the Microsoft 365 updates?” It is: “Which changes affect our tenant, and what do we need to do about them?”
A practical priority framework
ACT NOW → Changes that could stop synchronisation, block access or materially affect security if ignored.
PREPARE → Changes where the direction is clear and a controlled migration is sensible.
CHECK IF YOU USE IT → Changes that only affect a particular product, configuration or legacy integration.
The short version
| Change | Priority | Who needs to care? |
|---|---|---|
| Entra Connect minimum version | ACT NOW | Businesses using hybrid Active Directory and Entra Connect Sync |
| Passkeys and SMS/voice authentication | PREPARE | Most organisations with users still enabled for SMS or voice |
| Conditional Access Custom Controls | CHECK IF YOU USE IT | Organisations with older third-party MFA integrations |
| SharePoint pay-as-you-go storage | CHECK IF RELEVANT | Commercial tenants with storage pressure |
| Single hero link sharing | PREPARE | SharePoint and OneDrive users as the new experience reaches their tenant |
The table is deliberately not a list of six emergencies. It is a sorting tool. The first question for each item is whether your tenant uses the affected service.
ACT NOW: check Microsoft Entra Connect
Microsoft says that all Microsoft Entra Connect Sync services will stop working on 30 September 2026 if the installation is below version 2.5.79.0. This is a minimum-version requirement, not a suggestion to read the notice when somebody has time.
If you use Entra Connect Sync, check the installed version now. A failed synchronisation service can leave user changes, password changes and provisioning updates waiting on the wrong side of the hybrid boundary.
Entra Connect Sync is used by organisations that synchronise identities between on-premises Active Directory and Microsoft Entra ID. If it stops, the consequences may include user changes not flowing to the cloud, password changes not behaving as expected, provisioning delays, hybrid identity issues and avoidable administrative disruption.
This does not mean every Microsoft 365 customer has an Entra Connect problem. A cloud-only organisation that does not use Entra Connect Sync is not made vulnerable to this specific deadline simply because it has Microsoft 365 licences.
Who needs to check Entra Connect?
- Organisations with on-premises Active Directory.
- Organisations using Microsoft Entra Connect Sync.
- Businesses with a hybrid identity design.
- Managed service providers responsible for hybrid Microsoft environments.
- Businesses that are unsure whether an old server still performs synchronisation.
Do not rely only on somebody remembering that the system was upgraded once. Record the installed version, the server or servers involved, the person responsible, the upgrade path and a test that proves synchronisation works afterwards. Microsoft also lists prerequisites such as supported .NET and TLS versions, so the upgrade is not only a question of copying a new installer.
The business question
If this server stopped synchronising tomorrow, who would know, who could upgrade it and how would we confirm that identity changes are flowing again?
PREPARE: passkeys are replacing the SMS comfort blanket
Microsoft's current Entra guidance describes two different events. From 1 September 2026, users enabled for SMS or voice authentication may be automatically enabled for passkeys and brought into the passkey registration experience. From 1 February 2027, Microsoft-provided SMS and voice authentication is scheduled to retire for tenants that have not moved to a supported alternative or customer-managed telecom arrangement.
SMS MFA does not simply stop on 1 September 2026. September begins the passkey transition. The Microsoft-provided SMS and voice retirement date is 1 February 2027.
The direction is clear: Microsoft is trying to move organisations away from phishable authentication methods and towards stronger, phishing-resistant credentials. The operational work is to identify which users still depend on SMS or voice, choose suitable alternatives and test the recovery journey before Microsoft controls the pace of the change.
What should businesses review?
- Which users are enabled for SMS or voice in the Authentication Methods Policy?
- Which users have those methods registered, and which users actually use them?
- Can the relevant devices support passkeys, Windows Hello for Business or FIDO2 security keys?
- What will happen to users without a corporate smartphone or with accessibility requirements?
- Can a user recover access after losing a phone or security key?
- Are administrators, emergency accounts, contractors and remote workers covered?
- Does self-service password reset still depend on the retiring methods?
The strongest plan is not “turn on passkeys and hope.” Pilot the registration experience with representative users, communicate what will happen, provide a support route and test lost-device recovery. An authentication change becomes a business outage when the only person who understands it is unavailable.
Read the detailed IT Club guide to Microsoft's SMS and voice MFA retirement →
CHECK IF YOU USE IT: Conditional Access Custom Controls
Conditional Access Custom Controls are an older way to redirect a user to a compatible external service for an authentication or validation step. They are not a feature every Microsoft 365 tenant uses, and their presence in Microsoft's documentation does not mean they are active in your tenant.
Microsoft currently says that Custom Controls are deprecated. Adding new controls and editing existing controls will not be allowed from September 2026, while full retirement is scheduled for early 2027. Microsoft points organisations towards External MFA and the newer external authentication approach where appropriate.
This is a configuration-specific change, not a Microsoft 365-wide emergency. First establish whether your Conditional Access policies contain Custom Controls or a third-party integration that depends on them.
Who needs to check Custom Controls?
- Organisations using non-Microsoft MFA in Conditional Access.
- Businesses with older third-party authentication integrations.
- Tenants where a provider supplied JSON configuration for a Custom Control.
- IT providers managing legacy Entra configurations inherited from a previous supplier.
If you find one, record which policies use it, which users and applications are affected, who owns the third-party service and what the supported migration route is. Do not delete a working control in production simply because the retirement notice exists. Plan the replacement, test it with a pilot policy and keep a rollback decision documented.
CHECK IF RELEVANT: SharePoint storage is now more flexible
Microsoft's current commerce documentation describes Microsoft 365 SharePoint Storage as a pay-as-you-go service. As of June 2026 it is in public preview for commercial tenants, allowing eligible organisations to add and pay for SharePoint storage above their included quota as needed.
That can be useful for a tenant approaching its storage limit, but it is not a reason for every business to buy more capacity. Before spending money, check what is using the space and why.
- Large sites that no longer have a clear owner.
- Old versions retained far longer than the business requires.
- Retention policies that preserve data deliberately or accidentally.
- Unmanaged recordings, exports and duplicated project files.
- Sites created for projects that have already finished.
- The tenant's included storage and any current pricing or preview limits.
The business lesson
Buying more storage should not replace basic information housekeeping.
Public-preview availability also matters. A commercial tenant may see an option that is not available to education, government or 21Vianet customers. Confirm eligibility, billing, ownership and the current Microsoft terms before treating the service as part of a permanent budget.
PREPARE: the SharePoint and OneDrive sharing experience
Microsoft describes a new sharing model centred on a reusable single “hero link” for a file or folder. The aim is to make the link created by Copy Link, email sharing and the browser address bar part of one simpler sharing model instead of leaving users to manage multiple links with overlapping permissions.
This is primarily a usability and sharing-model change, not a reason to announce that existing permissions have suddenly disappeared. The exact rollout experience and timing can vary by tenant, so administrators should use Microsoft 365 Message Center and test the change with representative users.
- Explain to users what a hero link is and where they can review access.
- Check that existing external-sharing policies still express the intended boundary.
- Test links created from SharePoint, OneDrive, email and the browser address bar.
- Review how renamed or moved files behave in the new experience.
- Confirm that users understand a simpler sharing dialog does not make sensitive content public by default.
Do not invent a security impact that Microsoft has not documented. The important business task is to understand how the new experience represents access and to keep the organisation's sharing rules, user guidance and review process aligned with it.
Why this matters to SMEs
Microsoft 365 is a cloud service. Cloud services remove a great deal of infrastructure maintenance, but they do not remove the need to pay attention.
Someone still needs to monitor product retirement notices, authentication changes, minimum supported versions, licensing changes, security defaults, storage changes and feature deprecations. In a small business that person may be an owner, an internal administrator or an IT provider. The title matters less than the ownership being explicit.
Use Message Center for tenant-specific change
Public Microsoft news is useful for spotting a direction of travel. Microsoft 365 Message Center and Service Health are more useful for understanding notices that apply to a particular tenant, rollout ring or service configuration.
End users do not need to monitor Message Center. An administrator or IT provider should review it, decide whether a notice applies, record the action and communicate only what users need to know.
What should you do now?
- 1Check whether the organisation uses Microsoft Entra Connect Sync and confirm the installed version is at least 2.5.79.0.
- 2Review how many users still depend on SMS or voice authentication and plan passkey or other stronger-method registration.
- 3Search Conditional Access policies for Custom Controls and identify any third-party MFA integration that needs a migration plan.
- 4Review SharePoint storage use, retention and version history before deciding whether pay-as-you-go capacity is relevant.
- 5Watch Message Center for the new sharing experience and test it with a small group before writing new user instructions.
- 6Record each relevant change in a register with the owner, deadline, required action and verification step.
Microsoft 365 Security Checklist: 7 Controls Every Business Should Review →
What Your IT Provider Should Monitor →
Don't trust infographics blindly
A summary is useful for spotting something worth checking. The Microsoft source should decide what you actually do.
Microsoft dates move. Roadmap items change. Secondary summaries can simplify or misinterpret an announcement. Before making a production change, check the current Microsoft documentation, the tenant's Message Center and the configuration that is actually running in your organisation.
The IT Club view
Microsoft 365 changes are normal. The answer is not to panic every time Microsoft announces a retirement or new feature. Neither is it sensible to assume that cloud software looks after itself forever.
The useful question
Does this change affect our tenant, and if so, what do we need to do before the deadline?
The best Microsoft 365 change management is boring. Spot the change. Check whether it affects you. Fix it before it becomes a problem.
Not sure whether a Microsoft 365 change affects your business?
Ask the IT Club Advisor. Send us the Microsoft notice, screenshot or feature name and we’ll help you work out whether it actually needs action.
Sources and further reading
This is original IT Club editorial commentary based on current Microsoft documentation and Microsoft-authored product guidance checked on 12 September 2026. Microsoft rollout dates and preview availability can change, so administrators should verify the live tenant notice before making a production change.
Microsoft Entra Connect version release history →
Microsoft Entra Connect upgrade guidance →
Microsoft Entra passkeys by default and SMS/voice retirement →
Microsoft FAQ for SMS and voice retirement →
Microsoft Entra Conditional Access Custom Controls →
Microsoft migration guidance from Custom Controls to external MFA →
Microsoft 365 SharePoint Storage pay-as-you-go documentation →
Microsoft: the next step in sharing files in Microsoft 365 →
Plain-English Takeaway
The right response to a Microsoft 365 change is not panic or silence. Check whether it affects your tenant, assign an owner and complete the required action before the deadline.
Frequently asked questions
Which Microsoft 365 change needs action first?
If your organisation uses Microsoft Entra Connect Sync, check its version first. Microsoft says synchronisation services will stop working on 30 September 2026 for versions below 2.5.79.0. Cloud-only organisations that do not use Entra Connect are not affected by that specific deadline.
Is Microsoft stopping SMS MFA on 1 September 2026?
No. Microsoft says that from 1 September 2026 passkeys will be automatically enabled for users currently enabled for SMS or voice, with registration prompts and related policy changes. Microsoft-provided SMS and voice authentication is scheduled to retire on 1 February 2027, subject to the current Microsoft documentation.
Does Conditional Access Custom Controls retirement affect every Microsoft 365 tenant?
No. It mainly affects organisations using the older Custom Controls integration for external authentication or third-party MFA. Microsoft says new controls cannot be added and existing controls cannot be edited from September 2026, with full retirement planned for early 2027.
Is SharePoint pay-as-you-go storage mandatory?
No. Microsoft 365 SharePoint Storage is an optional pay-as-you-go service in public preview for commercial tenants. A business should understand its current storage use and retention behaviour before deciding whether additional capacity is necessary.
Related Articles
Microsoft 365 Admin Health Check: 15 Things Every Business Should Review
Microsoft operates the Microsoft 365 platform. Each organisation is responsible for how its own tenant is configured, who has access, whether data is protected and whether recovery is planned. This health check covers 15 areas every business should be able to answer.
Read article10 Microsoft 365 Features Your Business May Already Be Paying For
Microsoft 365 includes far more than Outlook and Teams. Here are ten useful features many businesses already pay for but rarely use — and how they could save you money.
Read articleMicrosoft 365 Mailboxes Are Moving to 100 GB – But Check Yours
Microsoft is rolling out 100 GB mailboxes for eligible Microsoft 365 Business plans — but the rollout is gradual, and some mailboxes remain at 50 GB. Here is what to check before buying another licence.
Read article