Writing
Field notes from the migrations.
Cornerstone writing on the EOL waves, the platform shifts, and the identity work happening right now in the Microsoft project space.
Deadline: Seven items, two days
Everything Microsoft retires on September 30 and October 1
Seven dated Microsoft items land across two consecutive days at quarter-end, and no Microsoft page lists them together. Organised by what actually happens: Entra Connect Sync STOPS below version 2.5.79.0; ConfigMgr 2503 stops being patched; Project Online and Publisher stop being available; Entra ID Protection risk policies stop enforcing silently; the CSP uplift costs money. And the Azure Migrate classic appliance already passed its final recovery point in May. Two items in the cluster use opposite date encodings.
Read the post →
Deadline: Live since Jul 22
Copilot GCC: a setting that processes data outside FedRAMP
Since July 22, 2026 non-federal GCC tenants have a Microsoft 365 admin center setting that enables Anthropic models in Copilot. It is off by default, and Microsoft states plainly that when enabled these models process Customer Data outside its FedRAMP-authorized U.S. Government cloud. Scoping it to a security group limits who can invoke it, not where processing happens. Separately, Anthropic models with Data Retention sit outside your Microsoft DPA entirely — Anthropic acts as an independent processor, with retention up to two years on flagged content.
Read the post →
Deadline: Two surfaces now
Exchange auth certificate renewal now has a second step
The Exchange auth certificate used to live only on your Exchange servers. Since the shared service principal was permanently blocked on October 31, 2025, it also lives in a dedicated Entra hybrid application — and renewing on-premises does not update it there. Worse, two Microsoft pages collide: one says run the Hybrid Configuration Wizard after replacing the certificate, the other warns that doing so re-uploads it to the first-party service principal you were told to purge for CVE-2025-53786.
Read the post →
Deadline: GA now — plan the exit
Autopilot device association: what removal requires
Windows Autopilot device association is generally available, and it works by writing a tenant affinity marker into the device's UEFI firmware. The catch is at the other end of the lifecycle: Microsoft states that removing association from Intune is not supported, and that deleting the device from the Intune list does not clear the marker on an already associated device. Removal needs elevated PowerShell run on the device — and if you clear it before unenrolling, the MDM re-associates on next check-in.
Read the post →
Deadline: v29 — 2026 wave 2
Business Central 29 removes SOAP on Microsoft's own pages
Most coverage says Business Central 29 removes SOAP. Microsoft's dated commitment is narrower: it removes SOAP for Microsoft's own UI pages, and deletes the Feature Management key that currently re-enables them. The giveaway is Microsoft's own third migration option — replicate the pages in a per-tenant extension and publish those as SOAP. There is a separate, broader deprecation with no version and no date. One is a deadline; the other is a direction.
Read the post →
Deadline: Publishing stops Sept
Dynamics 365 Release Planner retires by November 15
Three similarly-named things, only two of them retiring. Release plans stop being published to Microsoft Learn from September 2026 and Release Planner retires by November 15 — but release waves are a servicing cadence and are not going anywhere, so Business Central on-prem end-of-servicing dates are unaffected. The quiet sentence worth planning around: existing release plans remain available only 'until further notice', which is an intention rather than a commitment.
Read the post →
Deadline: Sept — month only
Entra custom controls stop accepting edits in September
Adding and editing Conditional Access custom controls stops being allowed in September 2026, with full retirement in early 2027. The trap is in Microsoft's own editing instructions: there is no in-place edit, so editing means deleting the control and creating a new one. Once creation is blocked, deleting one to change it is permanent. And per Microsoft's limitations, a custom control never satisfied a multifactor authentication claim in the first place.
Read the post →
Deadline: Read-only Sept 25
Microsoft Whiteboard: legacy boards deleted October 16
Whiteboards still in Microsoft's legacy Azure storage go read-only on September 25, 2026 and are permanently deleted on October 16 — Microsoft's words are 'permanently deleted and cannot be recovered'. September 25 is the date that actually constrains you, because that is when the migration route closes. Migration is user-triggered, so the boards least likely to migrate belong to the people least likely to open them. Microsoft Whiteboard itself is not retiring.
Read the post →
Deadline: Sep 30 — 25 days
Configuration Manager 2503 support ends September 30
ConfigMgr 2503 reaches end of servicing on September 30, 2026. Only three versions are supported today: 2503, 2509 and 2603 — and version 2409 quietly expired on June 6, 2026. Every Current Branch version gets exactly 18 months from its own release date, which is why these dates land on a Friday, a Wednesday and a Saturday rather than a Patch Tuesday. The reason it matters more than a normal lifecycle row: ConfigMgr is often the tool that patches everything else, so this is the control going unsupported, not the thing being controlled.
Read the post →
Deadline: Nov 3 — nothing errors
Entra memberOf rules retire November 3, 2026
After November 3, 2026 dynamic membership groups, dynamic administrative units and entitlement management auto-assignment policies that use the memberOf operator stop updating and remain in their last known state. Microsoft names the consequences itself: outdated Teams and SharePoint access, Conditional Access targeting, group-based licensing and access package assignments. The Conditional Access one is the expensive one — a policy scoped to a frozen group silently stops covering new joiners while still showing as enabled. There is no replacement operator yet.
Read the post →
Deadline: Auto-enrolling now
Passkeys became the Entra ID default on September 1
Most coverage leads with the ending — Microsoft-provided SMS and voice authentication retires February 1, 2027 with, in Microsoft's words, no opt-out option. That is not what is happening in your tenant this month. Since September 1 users enabled for SMS or voice are being automatically enabled for passkeys and prompted to register one during an authentication they were already performing. The prompt reaches your users before it reaches your project plan, and blocking it moves the work from September to February rather than removing it.
Read the post →
Deadline: P2 only — check first
Entra ID Protection risk policies retire October 1, 2026
Microsoft retires the legacy user risk and sign-in risk policies inside Entra ID Protection on October 1, 2026. The first question is whether it is your deadline at all: Microsoft's license table puts risk policies at P2 only, and P1 ships with Microsoft 365 E3 and Business Premium while P2 comes with E5. If it is yours, the replacement is two separate Conditional Access policies — and the Conditional Access Administrator role explicitly cannot disable the legacy policy it replaces.
Read the post →
Deadline: Claim window: Sept 30
M365 outage, August 2026: what the SLA actually pays
Microsoft's August 31 incident ran into September under one ID and hit ten Microsoft 365 services — Defender XDR among them, so the tool you would use to tell an outage from an attack was inside the failure. Separately, Microsoft's Volume Licensing SLA pays a service credit when measured uptime falls short. It is worth one month's fee for the affected service, you must choose one Service Level when an incident trips two, and a suite license does not unlock a claim per service. The conservative filing deadline is September 30, 2026.
Read the post →
Deadline: Six platforms, one Tuesday
.NET 8 LTS ends November 10, 2026, and PowerShell with it
Six Microsoft platforms end support on November 10, 2026: .NET 8 LTS, .NET 9, PowerShell 7.4 LTS, PowerShell 7.5, and Windows 11 23H2 on Enterprise and IoT Enterprise. PowerShell dies with .NET because it inherits the runtime's lifecycle — the successors share an end date too. And Windows 11 carries three dates a year apart, separated only by edition.
Read the post →
Deadline: M365: Oct 1, files included
Microsoft Publisher retires October 1, 2026
Most end-of-support dates are a risk decision — the software keeps running and you carry the risk. This one is not. Microsoft 365 subscribers lose Publisher after October 1, 2026 and, in Microsoft's own words, can no longer open or edit their existing .pub files. The perpetual version has a different date and keeps working. And Microsoft's bulk-conversion script needs a licensed Publisher install to run, so it has to be finished before the app goes away.
Read the post →
Deadline: Six 10.0s, nothing to patch
Entra ID RCE: six CVSS 10.0 CVEs you cannot patch
Microsoft published six CVSS 10.0 cloud-service CVEs on August 20, 2026 — an Entra ID remote code execution flaw among them — and every record reads customerActionRequired: false. There is no KB number, no maintenance window, and nothing your scanner could ever have found. What a mid-market tenant actually controls here is identity configuration, not patch cadence.
Read the post →
Deadline: Three costs, one budget cycle
What a 2026 infrastructure refresh actually costs
A VMware exit is not one cost. Broadcom's licensing changes, hosts that are mostly memory in the middle of a shortage IDC expects to run through 2027, and a 5% Microsoft CSP uplift landing October 1 all hit the same budget. The asymmetry is the argument: hyperscalers signed long-term agreements capping their memory increases. A firm buying three hosts did not.
Read the post →
Deadline: Not law — policy direction
Washington's first data privacy report and the mid-market
Washington's Attorney General published the state's first Data Privacy Report on August 14: 209 breaches in 2025, more than eight million residents, over four in five exposing Social Security numbers. Four days later, independent research put 73% of ransomware victims in the $10M–$1B revenue band. Nothing here is law. Both are worth reading anyway.
Read the post →
Deadline: The plant floor sets the plan
Manufacturing VMware exit: the plant floor sets the plan
A manufacturing VMware exit is not gated by the hypervisor. It is gated by a cutover window measured against production schedules, machine-attached workstations pinned to OS versions by warranty, and segments that genuinely cannot reach the internet. Which systems move first, which move last, and why the historian usually decides.
Read the post →
Deadline: The field is the hard half
Microsoft 365 migration with a field-mobile workforce
The office half of a Microsoft 365 migration is the easy half. Re-authentication is the migration event nobody schedules — and the users who cannot complete it are the ones you cannot reach by walking to a desk. Shared site devices, crews that change between phases, and connectivity that is genuinely intermittent.
Read the post →
Deadline: Census before wave plan
Litigation hold blocks the mailbox migration you planned
A mailbox on hold does not migrate cleanly, and most plans discover this mid-cutover. The hold census belongs before the wave plan, not during it. Retention policy, retention label and hold are three different things routinely conflated — and the decision to release one belongs to the firm's counsel, never to IT.
Read the post →
Deadline: The calendar, not the tech
The close cycle sets your migration calendar
In a finance organization the close cycle sets the migration calendar. Month-end, quarter-end, year-end and audit fieldwork eliminate most of the year, and what is left is narrower than any project plan assumes. Plus the part nobody designs up front: administrative access during the period is an audit artifact, not a convenience.
Read the post →
Deadline: End of Aug 2026 to opt out
EWS retirement: the August deadline most tenants miss
Configure an Allow List and set EWSEnabled=True by the end of August 2026 and your tenant is excluded from the October 1 flip that turns EWSEnabled from Null to False and blocks EWS for every app you run. The real trap is not the date — it is that Microsoft shipped two controls with almost the same name, and the obvious reading points at the wrong one.
Read the post →
Deadline: EOS Jan 12, 2027
Windows Server 2016 End of Support: ESU or Modernize?
Windows Server 2016 leaves extended support January 12, 2027 — and the same date takes Hyper-V Server 2016, IIS 10, WSUS, Defender, Storage Server 2016 and .NET 4.6.2, while the day before takes the whole System Center 2016 family. Backup and monitoring expire before the servers they cover, which inverts the usual sequencing. ESU is quotable as of August 13.
Read the post →
Deadline: Seven items, one day
Everything Microsoft retires on October 13, 2026
Seven Microsoft lifecycle items end on October 13, 2026 — and every table says October 14, because the cells carry a timestamp on the morning after the last supported day. A triage list: what actually stops, what only changes phase, and two places Microsoft's own summary page contradicts itself.
Read the post →
Deadline: 26.x out of servicing Oct 13
Business Central on-prem: the servicing clock nobody reads
Business Central on-premises versions carry about eighteen months of servicing each — but waves land twice a year, so a version drops out roughly every six months. 25.x lapsed in April 2026, 26.x lapses October 13. Two lapses in one calendar year, neither with an end-of-life headline attached.
Read the post →
Deadline: The split, in writing
Co-managed IT: what it actually covers
Co-managed IT is sold as a philosophy and bought as a division of labour. What your team keeps, what a partner takes, who holds which escalation, whose tenant the tooling lives in, and how project work differs from steady state. Includes the failure mode nobody sells against — your own senior people ending up as the escalation tier for someone else's junior bench — and the cases where co-managed is the wrong answer.
Read the post →
Deadline: Sync stops Sep 30, 2026
Entra Connect sync stops Sept 30: the version trap
Microsoft will stop all synchronization services in Entra Connect Sync on September 30, 2026 for any server below version 2.5.79.0 — password hash sync, joiner and leaver provisioning, all of it. The trap: 2.5.79.0 is itself scheduled to reach end of support on October 23, so the minimum upgrade buys about three weeks. And the fix lands on a Tier-0 server.
Read the post →
Deadline: Retires Sep 30 · recovery point already gone
Azure Migrate classic appliance retires September 2026
Azure Migrate's classic replication appliance retires 30 September 2026 — but the final recovery point for existing replications was 31 May 2026, a date already behind us. Anyone still replicating through it is in a degraded state now, not in six weeks. What to move to, and what memory pricing is doing to the host refresh that usually rides along with a VMware exit.
Read the post →
Deadline: Renamed from Azure Stack HCI
Azure Local as a VMware exit: what it is, what it costs
Azure Local is the product Microsoft used to call Azure Stack HCI — the old docs URL redirects to the new one. What it actually is, how per-physical-core pricing compares to Broadcom’s 16-core-per-socket minimum, whether it needs a live Azure connection, and the cases where plain Hyper-V is the more honest answer.
Read the post →
Deadline: Per host, not per core
XCP-ng as a VMware exit: free hypervisor, priced platform
XCP-ng is a Type-1 Xen hypervisor that Vates describes as having no limits and no license. The money is in Xen Orchestra and the Vates VMS bundle around it — priced per host, per year, with no CPU or RAM limits, which inverts the density penalty Broadcom’s core minimum creates.
Read the post →
Deadline: GP retires Dec 31, 2029
Dynamics GP retires end of 2029: what actually migrates
Microsoft retires Dynamics GP at the end of 2029 — on the Modern Lifecycle Policy, so there is no extended-support phase behind it. Microsoft points GP at Business Central and ships a migration tool. What that tool does to your chart of accounts, the four things it does not bring, and the place Microsoft’s own documentation contradicts itself.
Read the post →
Deadline: KEV added Aug 18 · due Aug 21
CISA KEV, August 2026: patch, then assume compromise
CISA added four CVEs to the Known Exploited Vulnerabilities catalog on August 18 — vCenter, SharePoint and Windows IKE among them. The three-day clock is routine and it binds federal civilian agencies, not you. What does transfer is the federal standard’s sequencing: patch, then run forensic triage to find out whether you were already compromised.
Read the post →
Deadline: Project Online retires Sep 30, 2026
Project Server end of support: three paths
Project Server 2016 and 2019 ended support July 14, 2026 — and the destination most teams name first, Project Online, retires September 30, 2026. It has a shorter remaining life than the thing you are leaving. Three real paths, the desktop's own October 13 date, and why the on-premises option is a SharePoint Enterprise decision wearing a different name.
Read the post →
Deadline: EOS Jul 14, 2026 · ESUs to Jul 2029
SQL Server 2016 end of support: ESU or upgrade?
SQL Server 2016 left extended support on July 14, 2026. The free-ESU-on-Azure-VM route that worked for 2012 and 2014 explicitly does not apply to 2016, and ESUs are delivered through Azure Arc. What they cover, what they cost, and the four real paths.
Read the post →
Deadline: CVE-2026-18577 · KEV Aug 3, 2026
Your provider's RMM is Tier 0: 8 questions to ask
An incomplete patch put an RMM platform on CISA's KEV catalog on August 3 — a bypass of a bug that was already fixed, reached through the tool's own remote-control feature. Why remote management tooling belongs in Tier 0, why 'patched' is a state you can lose, and eight questions your IT provider should be able to answer from memory.
Read the post →
Deadline: Suspended Jul 13, 2026 · RFI closed Aug 14
CMMC Phase 2 suspended: what defense contractors should do
The Department of War suspended CMMC Phase 2 on July 13, 2026 — the Nov 10 C3PAO mandate is off and Phases 3–4 are paused. But DFARS 252.204-7012 and NIST 800-171 self-attestation still bind, and with third-party assessment gone, an inflated SPRS score is a bigger False Claims Act risk. What changed, what didn't, and what to do now.
Read the post →
Deadline: Renewal-audit ready
Cyber-insurance readiness for the mid-market (2026)
Cyber-insurance renewal quietly became a security-controls audit — underwriters now verify MFA, EDR, and backups instead of trusting the checkbox. Where the 'MFA everywhere' gap reprices renewals and denies claims, backed by Coalition's 2026 claims data (BEC/FTF 58%, 70% dual extortion), and how to close it as a scoped 90-day readiness project.
Read the post →
Deadline: Agentic ID: 90-day cutover
Intune's June 2026 releases: STIG audits, shadow-AI control, agentic remediation
Three June 2026 Intune shipments for regulated mid-market IT: a Windows 11 STIG SCAP audit baseline (GCC High + Advanced Analytics), native shadow-AI detect-and-block for local AI agents like OpenClaw, and a Vulnerability Remediation Agent now on its own Entra agentic identity. What's base Intune, what's an add-on, and what's still preview.
Read the post →
Deadline: Oct 12, 2027 (consumer only)
Windows 10 ESU extended to 2027 — but not for your fleet
Microsoft quietly extended the free consumer Windows 10 ESU to Oct 12, 2027 — but it excludes every domain-joined, Entra-joined, and Intune-managed device you own. The two ESU programs, the registered-vs-joined trap, and the commercial cost ($61 → $122 → $244/device).
Read the post →
Deadline: Took effect Jul 1, 2026
Microsoft 365 prices rose July 1, 2026 — what to do now
Microsoft's new commercial pricing took effect July 1, 2026 — E3 $36→$39, E5 $57→$60, Business Basic $6→$7, Frontline up 25–33%. The pre-increase lock-in has closed, but the renewal-boundary mechanic still sets what you pay, and it is the playbook for the next increase.
Read the post →
Deadline: Jul–Nov 2026 stack
IT layoffs vs. 2026 deadlines: who runs the work?
H1-2026 tech cuts collided with a stacked Microsoft EOL calendar. When a team shrinks, the SharePoint, Exchange, and CMMC deadlines don't move — how a senior bench fills the gap without touching headcount.
Read the post →
Deadline: Aug 2026 SU kills OWA Light
Exchange Server SE: what modern servicing commits you to
You're on Exchange Server SE — now what? Single-version modern servicing, mandatory CU currency, the cloud dependency for on-prem servers, Server Core, and the coming product-key requirement. The August 2026 security update permanently disables OWA Light — and the KB never says so.
Read the post →
Deadline: SE CU2, date unannounced
Exchange SE CU2: the coexistence deadline after EOL
Exchange 2016/2019 are out of support; the paid ESU bridge ends Oct 2026. SE CU2 will block coexistence with legacy Exchange — closing the last clean migration window. The senior operator's runbook.
Read the post →
Deadline: Governance: 90-day playbook
Copilot governance one year on: the 12,000-permission reckoning
One year after the oversharing warning, mid-market Copilot tenants are leaking HR, finance, and legal docs. The 90-day playbook using Purview DSPM, SharePoint Advanced Management, and Restricted SharePoint Search.
Read the post →
Deadline: RC4 phase knob removed Jul 2026
Kerberos RC4 April 2026 enforcement: mid-market triage runbook
Microsoft's April 14 patch flipped DCs to AES-SHA1-only and broke RC4 service-account logins. The 3-hour triage runbook, and what the July 2026 updates actually remove.
Read the post →
Deadline: Period 2 is an enrollment gate
Exchange ESU Period 1 expired — your real deadline
The paid Exchange ESU bridge is nearly spent: Period 1 expired April 14, 2026 and Period 2 ends October 2026 (final). Only Period 2 enrollees receive the May–October 2026 updates — management-only hybrid servers included. The real deadline, four exit paths, and hour ranges for 50–1,500 seats.
Read the post →
AD functional level on Windows Server 2019/2022: not stuck at 2016
Microsoft skipped Server 2019 and 2022 functional levels. Server 2016 IS the maximum for any 2019/2022 forest. What Server 2025 (behavior version 10) actually adds.
Read the post →
Deadline: Identity-substrate
AD Tier-0 in 90 days: the mid-market edition
Microsoft's enterprise Tier-0 guidance is overkill for 100–500-user shops. The four controls and 12-week plan that close 80% of the gap at under 25% of the cost.
Read the post →
Deadline: M&A integration
M&A tenant merge in 60 days: the reference playbook
A worked reference scenario for folding a subsidiary tenant into a parent: two M365 tenants, one identity model, 60 days from legal close. Power Platform sprawl, externally shared apps, Teams chat fidelity, OneDrive personal data.
Read the post →
Deadline: Phase 2 suspended Jul 2026
CMMC L2 pre-assessment: what $15K buys you
A fixed-fee $15K pre-assessment for a 100–300-user GovCon shop — SSP draft, POA&M draft, GCC High eligibility, NIST 800-171 gap register, third-party app compatibility, two weeks.
Read the post →
Deadline: Renewal-driven
VMware to Azure vs Hyper-V: 500-VM decision guide
Six dimensions that decide whether a 500-VM mid-market VMware exit lands in Azure IaaS or Hyper-V on-prem. Two anonymized walk-throughs and a decision matrix.
Read the post →
Deadline: EOL passed + 2 exploited CVEs
SharePoint 2016 & 2019 EOL July 14, 2026: three paths
SharePoint 2016 and 2019 hit end of support July 14, 2026 — no ESU at any price — and two actively-exploited flaws have landed since, including CVE-2026-50522 at CVSS 9.8. Project Server and SQL Server 2016 died the same day. SPO migration, Subscription Edition, or selective hybrid, with cutover math for 50/200/500 users.
Read the post →
Deadline: Pre-rollout
Is Microsoft Copilot HIPAA compliant? Read the BAA
Microsoft's BAA covers the platform, not your tenant configuration. The four pre-deployment fixes that keep Copilot on the right side of HIPAA.
Read the post →
Deadline: Renewal-driven
After Broadcom: 250-VM Hyper-V migration in 90 days
Anonymized field notes — $310K Broadcom renewal turned into a $35K Hyper-V migration with a four-month payback.
Read the post →
Deadline: Jan 12, 2027 (Server 2016)
Windows Server 2019 EOS: real upgrade options for 2026
Windows Server 2019 is out of mainstream support and Server 2016 ends January 12, 2027. The real upgrade paths — in-place to Server 2025, rehost, or Azure — and the AD functional-level facts most teams get wrong.
Read the post →
Deadline: SE CU2, date unannounced
Exchange Server 2019 EOL: your real migration deadline
Exchange 2016/2019 lost support Oct 14, 2025; the paid ESU bridge ends Oct 2026. The four migration paths and the deadline that actually bites: SE CU2.
Read the post →
Deadline: Renewal-driven
VMware after Broadcom: your real exit options
vSphere → Hyper-V vs Nutanix vs Scale Computing vs Azure Local vs Proxmox. When each lands.
Read the post →
Deadline: Pre-rollout
Copilot readiness: the 12,000-permission problem
Why oversharing becomes a data-loss event when Copilot turns on, and how to fix it before you flip the switch.
Read the post →
Deadline: Phase 2 suspended Jul 2026
GCC High before CMMC Phase 2
The Nov 10, 2026 C3PAO mandate was suspended in July 2026 — what still binds, realistic GCC High timelines, common mistakes.
Read the post →
Tenant-to-tenant M365 migration: a playbook
The M&A and divestiture story, what tools fit when, and how to budget realistically.
Read the post →
Stay in the loop
Follow Pro IT NW on LinkedIn for new field notes.
No newsletter, no signup form — just LinkedIn notifications when we publish.