Blog · 6 min read ·
ShareEverything Microsoft retires on September 30 and October 1
Seven dated Microsoft items land on September 30 and October 1, 2026: Entra Connect Sync stops synchronizing below version 2.5.79.0, the Azure Migrate classic replication appliance retires, Configuration Manager 2503 leaves servicing, Project Online retires, Entra ID Protection legacy risk policies retire, Microsoft Publisher goes for subscribers, and the CSP cost-of-capital uplift applies at renewal.
Two consecutive days at the end of this month carry seven separate dated Microsoft items. That clustering is a coincidence of quarter-end scheduling rather than a plan, but the effect on a mid-market IT team is real: one change window, several unrelated systems, and no single Microsoft page that lists them together.
The useful way to organise them is not by product. It is by what actually happens when the date passes, because that determines whether you need a project, a change record, or a conversation with finance.
Things that stop working
Entra Connect Sync — September 30. This is the one to check first. Microsoft's installation prerequisites carry the notice under a heading reading "Mandatory Upgrade Required": synchronization services stop working on September 30, 2026 on any server below version 2.5.79.0. Not "unsupported" — stops. Directory sync failing means new starters do not appear and leavers are not disabled, which is a security problem within a week and an audit problem within a month. The version trap is worth reading in full, because the minimum version to survive the date is itself retired three weeks later.
Things that stop being maintained
Configuration Manager 2503 — September 30. End of servicing. The console opens, the deployments run, and the platform stops receiving security updates. The wrinkle here is what ConfigMgr is: frequently the tool that patches everything else, which makes this the control going unsupported rather than the thing being controlled. Only three versions are supported today, and one of the expired ones went quietly in June.
Things that stop being available
Project Online — September 30. Retirement under Modern Lifecycle Policy. Three paths out, and a decoding note below that matters.
Microsoft Publisher — October 1. The unusual one, because most end-of-support dates leave you carrying risk while the software keeps running. This one takes away access: Microsoft 365 subscribers lose the ability to open and edit their existing files. The perpetual version has a different date and keeps working.
Things that stop enforcing, silently
Entra ID Protection legacy risk policies — October 1. The failure mode here is the one this blog keeps returning to: nothing errors. A tenant that does nothing simply stops applying risk-based access control, which is exactly the control a cyber-insurance questionnaire and a compliance narrative both assert is in place. The first question is whether it is your deadline at all — these are Entra ID P2 features, and E3 and Business Premium do not include P2.
Things that cost money
The CSP cost-of-capital uplift — October 1. A 5% increase applying at renewal to CSP software subscriptions with annual-term commitments billed monthly, including Windows Server, SQL Server, CALs and System Center. Annual and month-to-month billing are unaffected. This is separate from the July 1 price rise and lands on a different set of lines. It is a budget conversation rather than a technical one, which is precisely why it tends to reach IT after the invoice rather than before.
The one that has already passed its point of no return
Azure Migrate classic replication appliance — September 30. Microsoft's wording, quoted in our note on it: “Classic replication appliance is retiring on 30 September 2026. Final recovery point for existing replications will be on 31 May 2026.”
Read those two sentences together. The retirement is three weeks away; the last usable recovery point was over three months ago. If you have an in-flight replication on the classic appliance, it is not approaching a deadline — it passed the useful one in spring and nobody was told loudly. September 30 closes something that has already stopped being able to do its job.

A decoding note, because two items here disagree
Microsoft's lifecycle tables use two different conventions, and both appear in this cluster:
- Configuration Manager 2503 renders as
10/1/2026 6:59:59 AM— the morning after the last supported day. Subtract one day: end of day September 30. - Project Online renders as
9/30/2026 8:00:00 AM— which is literal. September 30 means September 30.
Two items, two days apart, opposite encodings. ⚠️ Apply one habit across a lifecycle page and you will be one day wrong on roughly half of it. Read the time component on every row, every time.
What does not belong on this list
EWS retirement. Microsoft's page reads "October 2026: EWS starts to be disabled globally for all organizations" and separately "April 2027: EWS is fully disabled." Those are different verbs, and October is the start of a six-month rollout with no published day. Copy that puts EWS on October 1 has invented a date. The opt-out deadline that actually matters now runs to the end of September 2026, per Microsoft's EWS retirement post — a separate Microsoft Learn page written for Skype for Business Server hybrid customers still gives an end-of-August date, so confirm which page applies to your migration path before you plan around either one.
Also landing at month-end, with no fixed day
One more Teams admin center change lands in the same window without a specific date attached, which is why it is not counted among the seven above — but a team managing Teams Rooms or Teams Phones should not miss it either. Microsoft is deprecating the Android device management features in the Teams admin center (TAC) in favor of the Teams Rooms Pro Management Portal (PMP). Per Microsoft Learn: “The phased deprecation of the device management features in TAC will start in the September 1st week, 2026 and expect to complete by end of September 2026,” with the final phase “Decommissioning the overlapping Teams device management features in TAC” and PMP becoming “the primary management portal.” Affected devices are Teams Rooms on Android, Teams Phones, Teams Panels, and SIP devices; management of Teams Displays is not migrating and stays in TAC. Teams Phones already enrolled in TAC auto-enroll in PMP once they update to Admin Agent version AA 830 or later, and GCC, GCC-High, and DoD tenants will have their devices auto-updated to the newer AA 856 agent ahead of the cutover. A related Learn article on update management adds a separate warning: organizations that do not start managing updates for their Android devices in PMP before the corresponding capability retires in TAC risk losing updates-management capability for those devices altogether. Pull a device inventory from TAC now, while it still shows one, and flag anything offline or signed out for a closer look.
What we would do this week
- Check the Entra Connect Sync version first. It is the only item on the list where something stops. Everything else degrades, expires or invoices.
- Ask four inventory questions, not seven. Do we run Entra Connect Sync below 2.5.79.0? Do we run ConfigMgr, and on which version? Do we have Project Online or Publisher users? Do we hold Entra ID P2? Four answers cover the whole cluster.
- Send the CSP uplift to whoever owns the renewal, today. It applies at renewal, so the useful moment is before the quote, not after.
- If the answer to everything is no, write that down with the date. A dated nil return is a real artefact and it takes ten minutes. It is also what you will wish you had when somebody asks in November.
If you only get one change window
Seven items landing inside forty-eight hours at quarter-end is a scheduling problem as much as a technical one, and most mid-market teams will get one window rather than seven. Sequence by blast radius rather than by date:
- Entra Connect Sync. It is the only item that stops a running service, and its failure reaches every downstream system that trusts your directory. Nothing else on the list competes with it.
- Entra ID Protection risk policies, if you hold P2 — because the failure is invisible and the control it removes is one you have probably asserted in writing to an insurer.
- Configuration Manager. Slower to hurt, but it degrades your ability to fix everything else.
- Publisher, Project Online and the CSP uplift. These are communications and procurement tasks, not change-window tasks. They can be handled by email.
The Azure Migrate appliance is not on that list on purpose. Its useful deadline is behind you, so it belongs in a decommissioning conversation rather than a change window.
Sources
Each item above is covered in more depth on its own page, and each of those carries the Microsoft source it was verified against — Entra Connect Sync, Azure Migrate classic appliance, Configuration Manager 2503, Project Online, Entra ID Protection, Microsoft Publisher and the CSP price change. The dates in this post were checked against those pages on September 5, 2026.
See also everything Microsoft retires on October 13, 2026 — a larger cluster two weeks later, including Office, Project and Visio LTSC 2021, Windows Server 2012 ESU Year 3, and Windows 10 Enterprise 2016 LTSB.
If you would rather have the four inventory questions answered and the remediation scoped as a bounded piece of work, scope it with us.
Questions we get asked
- What actually lands on September 30 and October 1, 2026?
- Seven dated items. On September 30: Microsoft Entra Connect Sync stops synchronizing on servers below version 2.5.79.0; the Azure Migrate classic replication appliance retires; Configuration Manager 2503 reaches end of servicing; and Project Online retires. On October 1: the legacy risk policies in Entra ID Protection retire; Microsoft Publisher stops being available to Microsoft 365 subscribers; and Microsoft's CSP cost-of-capital uplift starts applying at renewal.
- Which one is most urgent?
- Entra Connect Sync, because it is the only one where the verb is 'stops'. Microsoft's own notice sits under a heading reading 'Mandatory Upgrade Required' and states that synchronization services stop working on September 30, 2026 if you are not on at least version 2.5.79.0. Directory synchronization failing is not a support conversation — it is new starters not appearing and leavers not being disabled.
- Is any of this already too late?
- One item, partially. The Azure Migrate classic replication appliance retires on 30 September 2026, but Microsoft's guidance states the final recovery point for existing replications was 31 May 2026 — a date that has already passed. Any in-flight replication on the classic appliance is already beyond its last recovery point, so the September date closes something that stopped being useful months ago.
- Do all these dates use the same encoding on Microsoft's lifecycle pages?
- No, and that is the trap. Configuration Manager 2503 renders as '10/1/2026 6:59:59 AM', which is the morning after the last supported day, so it decodes to end of day September 30. Project Online renders as '9/30/2026 8:00:00 AM', which is literal. Two items in the same two-day cluster use opposite conventions, which is why the rule is to read every row rather than apply one decoding habit across a page.
- Does EWS belong in this cluster?
- No, and putting it here would be a mistake we see made often. Microsoft says EWS 'starts to be disabled globally for all organizations' in October 2026 with no specific day, and describes full disablement in April 2027. October is the beginning of a six-month rollout, not a date. Anything claiming EWS switches off on October 1 has invented a precision Microsoft did not publish.
Related service
Microsoft 365 migrationWritten by the team at Pro IT NW · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.