What's new for MSPs: September 2026
Welcome to an exciting new series tailored for the evolving world of Managed Service Providers (MSPs)! I’m Bryan Irwin, and in this blog series, I’ll be offering practical tips and insights aimed at helping MSPs thrive alongside Microsoft.
As an MSP, your role is to turn software into impactful applications. You take a product announcement and transform it into a usable configuration, provide security advice that safeguards your clients, and leverage licensing updates to create new business opportunities. Your work shapes how customers interact with Microsoft products, and we want to ensure that both your experience and theirs are top-notch. We understand that your requirements differ significantly from those of larger enterprise IT teams, as you juggle multiple tenants, each with its own needs and expectations. This task demands an extensive knowledge base that can be tough to maintain while also keeping those tenants secure and productive.
So, what can you expect in these blog posts? You’ll find valuable guidance from Microsoft, insights from our ‘For MSPs’ partners, and advice from MVP practitioners. Anticipate product updates, partner viewpoints, and lessons drawn from real-world customer scenarios.
Thank you for choosing to build your enterprise on our platform. We encourage you to share your learning interests in the comments section, and we’ll respond with relevant content. Let’s dive into our first edition!
Jump to: Microsoft updates | Roadmap details | Resources | Partner solutions | MVP insights | What’s next
First up: How to effectively manage a service practice in the AI era
September 22, 2026 – 8:00 AM PT | 3:00 PM UTC
Join Kelvin Tegelaar, CTO at Lime Networks and Microsoft MVP, as he explores how to establish a disciplined AI operating model. He will share best practices for safeguarding client data, standardizing tenant configurations, linking automation with PSA and RMM platforms, and clearly defining responsibilities for significant decisions.
Got a topic you’d like us to cover in a future gathering? Please take the Meetups for MSPs survey.
Microsoft Intune Suite: Unattended Remote Help for Windows
- Why it matters: Enabling remote sign-in could allow technicians to assist with customer devices when users are unavailable, particularly during off-hours support and automated service tasks.
- Suggested action: Assess whether unattended support could lower desk-side interventions in customer environments. Before proceeding, ensure that licensing, permissions, auditability, security measures, customer consent, and supported Windows scenarios are in place.
- Current roadmap status: Now generally available as of August 2026
Microsoft 365 Backup: Configurable recovery window
- Why it matters: A configurable recovery window for Backup opens up direct discussions with customers, influencing compliance talks, backup scope, design approaches, recovery promises, and storage strategies.
- Suggested action: Investigate how the adjustable retention fits with existing backup services and your customers’ recovery expectations.
- Current roadmap status: Being rolled out as of August 2026
Microsoft 365 Backup: Full-workload backup
- Why it matters: A full-workload policy model can streamline backup setups and standardize approaches across customer environments.
- Suggested action: Determine if Full Workload Backup could enhance consistency across customer tenants and simplify ongoing backup administration. Compare this new capability with the MSP’s current backup operating processes before adjusting service designs.
- Current roadmap status: Public Preview phase
Lior Bela continues to advocate for MSPs! Don’t miss his new series Trust Before Hype starting Thursday, September 24 (and continuing every two weeks). He will also discuss the Future of the MSP in an AI-Driven World: Security, Governance, & Opportunities on Friday, September 25.
Your clients spend much of their day using web browsers, yet many companies don’t actively manage or secure this crucial area. Discover practical guides to tackle common customer dilemmas — including onboarding contractors and managing bring-your-own-device (BYOD) scenarios, data protection, shadow AI safeguards, branding options, and extensions — all while creating new service offerings with Edge for Business.
New to browser management? The MSP one-pager explains why browser security is essential and how it integrates with the Microsoft stack you’re already using. The license matrix outlines which Edge for Business features are included with various Microsoft 365 licenses.
The rise of AI has sparked new conversations among clients about data security, compliance, and governance of information. Many recognise the urgent need to understand and protect their data before fully embracing AI, but they often aren’t sure where to begin. The Security Partner Toolkit is a comprehensive set of interactive tools and guidelines designed to smooth this path, covering everything from initial positioning to deployment. Here’s what’s available in the toolkit:
Asset | When to use it |
Industry one-pagers | First customer engagement as a starting point for discussing data protection or as follow-up materials after client meetings. |
Data security guided assistant | During discovery and scoping with new clients or those lacking an existing labeling strategy, build a clear plan, co-create labels, and develop DLP policies. |
SOW Generator | After discovery or during proposal creation. Use this as a customizable framework, rather than a simple cut-and-paste job. Currently focused on Purview engagement only. |
Security SMB deployment guides | Planning and implementing Business Premium, Purview Suite, and Defender Suite |
PowerShell deployment scripts | During implementation — clone, run What-If, review, then apply in a test tenant first. |
Your feedback on these resources will guide future adaptations. Let us know which materials you plan to use in your practice, the customer situations or use cases you’re tackling, and where you feel more guidance or automation would bring the highest value. Share your thoughts and your intended use cases.
What it is: A feature within AvePoint Elements Workspace Management described as “a single multi-tenant dashboard for discovering, monitoring, and optimising AI agents across customer environments.”
This encompasses Microsoft 365 Copilot, including both personal and chat agents, Copilot Studio, and SharePoint agents. Here’s what this feature offers:
- Identifies and inventories AI agents across all customer tenants
- Displays usage patterns, adoption trends, and identifies inactive agents
- Flags inactive agents to inform licensing and cost strategies
- Shows which labelled and sensitive data agents have accessed
Find out more by reading Introducing AI Agent Management if you:
- Manage multiple Microsoft 365 tenants but are unsure how many AI agents are operating or what data they interact with
- Are packaging AI governance as a billable service
- Have clients deploying Copilot Studio or SharePoint agents without a clear ownership model
Note: This information is vendor-published and cites AvePoint’s own Road to AI Readiness study. Please confirm details regarding pricing, licensing, and availability with AvePoint prior to using this content with customers.
What it is: A bi-weekly update covering approximately 20 enhancements and fixes, which include:
- Self-hosted migration now supports the latest infrastructure updates
- Message Trace has been rebuilt on Graph, providing historical search and mail-flow statistics
- JIT and PIM role templates that don’t require an Entra ID P1 or P2 license
- Certificate-only SAM authentication streamlining secret-less configurations
- A complete overhaul of quarantine, GDAP role templates, per-user MFA at user creation, and improved paging for large tenants
Take a look at the v10.10.0 release notes if you:
- Operate CIPP self-hosted. The release notes indicate that there’s no support for self-hosted instances, so plan your migration accordingly.
- Work with message tracing or quarantine across multiple customer tenants.
- Rely on the Best Practice Analyzer or the classic dashboard; both will be removed in October, signifying a change in your tasks.
- Manage large tenants where paging performance has been an issue.
Note: Several hotfixes have been released since this announcement, so ensure you apply the most current version. Additionally, the front end has transitioned from MUI v7 to MUI v9, so be aware that some things may look different. It’s a good idea to inform your technicians about this when they open a ticket.
CyberDrain maintains an open community. Join the discussion at r/MSP on Reddit, on LinkedIn, and via Discord.
What it is: A multi-tenant threat detection and response feature designed for MSPs. This capability allows you to identify, investigate, contain, and report threats across Microsoft 365 customer environments from a single platform. It enhances the management of Microsoft 365 configurations into a broader security management solution that:
- Monitors Entra ID, Exchange, SharePoint, Teams, Defender, and Purview across customer tenants
- Correlates identity, privilege escalation, data exfiltration, email and messaging, and app/API signals into incidents using AI-powered detection validated by SOC
- Offers a multi-tenant incident view, detailing events, affected users and services, and the progression of the attack
- Includes response measures such as locking compromised accounts, revoking active sessions, and retracting harmful emails
- Produces forensic reports and customer-ready documentation, while highlighting relevant Microsoft 365 policies or settings that could have mitigated incidents
Explore Threat detection and response designed for MSPs managing Microsoft 365 if you:
- Oversee security operations across multiple Microsoft 365 tenants and wish to view incidents in one interface
- Require built-in containment measures and client-ready reporting rather than just alerts
- Desire to link incident response back to configuration improvements across your client base
A free trial is available.
Before you quote it: This information comes from a vendor and includes claims about AI-powered detection, SOC validation, supported workloads, response actions, and preventative recommendations. Confirm details regarding pricing, licensing, tenant prerequisites, data handling, service coverage, and contractual response commitments before sharing with clients. inforcer states that TDR is generally available to MSPs.
What it is: A practical guide to the Intune Management Extension (IME), the Windows agent facilitating Win32 application deployment, PowerShell scripts, remediation, custom compliance discovery, and device queries. When an application or script fails, vital evidence resides on the device rather than in the Intune console, so troubleshooting the IME is an essential service desk skill. This guide will teach you:
- The purpose of the Intune Management Extension and its significance for Intune
- How the agent operates (service, check-in frequency, and execution context)
- Common log files that resolve frequent IME issues
- A troubleshooting blueprint for stalled apps and silent scripts
- How the IME interacts on Windows 365 Cloud PCs and Azure Virtual Desktop session hosts
- Where Nerdio Manager extends Intune for both cloud desktop paths, impacting your Cloud PC and session host groundwork
- Common queries involving the Microsoft Intune Management Extension
Check out Understanding the Intune Management Extension if you:
- Deploy Win32 applications or PowerShell scripts across customer tenants and want a systematic diagnostic procedure for your service desk
- Are training new technicians who escalate app installation issues without checking device logs first
- Wish to convert ad-hoc troubleshooting into a documented guideline
You can also watch an on-demand webinar discussing the latest Nerdio Manager for MSP updates.
What it is: An educational program tailored to suit your pace, featuring on-demand modules that let you start with the fundamentals, build your confidence, and advance to a more comprehensive setup at your own rhythm. Focus on what matters most and progress as quickly or slowly as suits your needs, with:
- Free video courses – Brief, focused demos and lessons released weekly, spanning Intune fundamentals to advanced topics
- Progress tracking – Mark lessons as finished, pausing and resuming where needed, with visual indicators that help motivate you throughout the course.
- Personal clinics – Book individual sessions with an Intune specialist to receive tailored advice on your specific deployment challenges.
- Completion badge – Finish the Academy and earn a digital badge celebrating your progress and commitment to enhancing your Intune skills.
- Regular office hours – Attend live community-led sessions to explore real-life scenarios and receive support from peers and industry experts.
- Community engagement – Connect between sessions in a dedicated space to pose questions, share experiences, and tap into the wisdom of fellow Intune admins.
Sign up for the waitlist at https://intune.academy if you:
- Manage Intune across multiple tenants and desire a consistent approach rather than tailored strategies for each customer
- Onboard technicians who require structured Intune training without additional budget allocations
- Handle Intune alongside other responsibilities and seek a reliable method for its management
Note: This is a vendor-operated program currently in development, so course content and schedule may evolve as the inaugural group progresses.
Materials authored by MVPs are offered for informational purposes and reflect the creators’ perspectives, not necessarily those of Microsoft. Microsoft has not independently verified or endorsed these materials. Always confirm technical, security, compliance, licensing, and business guidance with current Microsoft documentation and your requirements before taking action.
What it is: A collection of Intune content compiled into a single timeline, summarised as “real-time updates from Microsoft Intune blogs, community authors, and official documentation, directly delivered without algorithms.” Here’s a glimpse into the popular feeds and features:
- Radar aggregates community blog articles, YouTube channels, and quick updates from selected sources, tagged by topic.
- Sonar and Docs Radar track changes in Microsoft 365 Message center item and official documentation separately from community posts.
- A conference calendar lists community events related to Intune and open calls for papers, integrating with Sessionize and Meetup.
- Authors can contribute their blogs through an RSS feed, suggest a YouTube channel, register an event, or exclude individual entries from Radar.
Explore IntuneFans FAQ and visit IntuneFans if you:
- Want to keep track of Intune updates across various blogs and prefer a consolidated timeline
- Need to monitor changes in the Microsoft 365 Message center and documentation that impact customer tenants
- Publish your own Intune material and want to share it with the community, or wish to participate in events and get your sessions highlighted
- Plan conference travel and want information about Intune community events and CFP deadlines all in one place
Source: Simon Skotheimsvik
Before you use it: The IntuneFans website aggregates community-generated content alongside Microsoft sources. Aggregation does not entail validation, so verify any technical claims against the original post and Microsoft documentation.
What it is: An article featuring strategies to avoid creating an “exception factory” when application-control policies are introduced without a supporting operational model. It presents five methods for keeping an enforced policy manageable: Managed Installer, supplemental policies, clearly documented exceptions, deployment rings, and rollback planning. The article highlights crucial points, such as:
- Managed Installer tagging is not retroactive; thus, applications installed before the configuration was implemented on the device do not become trusted.
- Delivery might take up to 30 minutes post-policy activation, and the Managed Installer overview might take as long as 24 hours to update the device’s status.
Read App Control for Business Part 2: How to Avoid the Exception Factory if you:
- Are considering enforcing application control for a client and haven’t yet established the exception procedure
- Currently implement App Control and notice that handling exception requests is becoming increasingly time-consuming each month
- Want application control to function as a repeatable managed service instead of a one-off deployment
Source: Dustin Gullett
Before quoting it: This article reflects the author’s interpretations. Confirm statements regarding supported behaviour, join requirements, and limitations with the linked Microsoft documentation.
What it is: A guide detailing how the inventory and investigation capabilities of Intune facilitate discussions about unmanaged local AI agents, exemplified through OpenClaw. The suggested sequence is discover, investigate, then control, as blocking first could disrupt authentic Node.js or Windows Subsystem for Linux functionalities. Additional insights from the article include:
- The control step employs the Local AI Agent Baseline – OpenClaw (Preview), which introduces two firewall rules, both blocking TCP outbound traffic from Node.js executables.
- Microsoft is straightforward about the limitations: “These settings might not fully block all agent execution paths,” and the baseline “might also hinder other processes apart from OpenClaw.”
- Intune inventory applies to corporate-owned, Intune-managed Windows devices that are Microsoft Entra joined or hybrid joined, with initial data potentially taking up to 24 hours
- The Shadow AI view in the Microsoft 365 admin console necessitates opting into the Frontier preview, enrolling in Microsoft Defender for Endpoint, and holding a Microsoft 365 E5 licence.
Read Detect and Block Shadow AI with Intune: OpenClaw in Practice if you:
- Have clients inquiring about AI tools operating on their devices but can’t provide answers yet
- Support developer or engineering clients where Node.js and WSL are daily tools
- Are incorporating endpoint AI governance into a security service and need a starting approach
Source: Jannik Reinhard
Before you quote it: This baseline is in preview mode. Confirm support, prerequisites, and licensing, and try against legitimate developer tasks and Microsoft documentation before widespread deployment.
What it is: A guide on Multiple Managed Accounts, allowing users to hold several MAM-enabled accounts within a single app, each governed by its own app protection policy. This scenario is common for consultants: for instance, an engineer with a managed account at their workplace alongside another at a customer’s site. Here’s what you’ll observe in action:
- Currently available on Teams for iOS and iPadOS versions 8.10.0 or later, and Outlook for iOS and iPadOS versions 5.2626.0 or later
- Microsoft advises that the feature “is rolling out gradually and may not yet be accessible in your tenant”
- One account can be MDM and MAM managed while additional accounts are MAM-only. Multiple MDM is not supported, and wrapped applications are not in scope
- Teams displays one account at a time. In contrast, Outlook shows multiple accounts, and Microsoft states that “Mixed views always enforce the most restrictive behaviour,” which blocks cut, copy, paste, and screen capture
- The IntuneMAMAllowedAccountsOnly key limits an application to a single managed account on managed devices
Read Using multiple managed accounts with app protection policies if you:
- Have technicians operating across both their tenant and customer environments from mobile devices
- Are aiding engineers navigating a merger or acquisition with accounts in two separate tenants
- Plan a workflow reliant on copying and pasting between accounts, knowing that mixed-view lockdown will block this
Source: Peter van der Woude
Before you quote it: Verify app versions, the scope of platforms, and the rollout status in each tenant before designing around this.
What it is: A three-part series transitioning from mechanisms to automation and finally architecture. The series begins with terminology since the models are not equivalent. Microsoft defines device association as “a Windows Autopilot device preparation feature that binds a Windows device to your organization before it enrolls with a mobile device management (MDM) provider.” Windows Autopilot and Windows Autopilot device preparation are the deployment solutions; device association is an optional feature providing early knowledge of the organization. The series includes:
- Technical deep dive. Windows Autopilot Device Association, detailing the entire flow: exporting the DeviceLink identity, discovery, TPM-backed validation, the signed association stored in UEFI, and Windows retrieving the OOBE settings for device preparation.
- Practical automation. Windows Autopilot Device Association: Somebody has to be the OEM: highlighting that OEM and partner pre-association is not available, meaning manual effort is required. This article introduces Get-AutopilotDeviceAssociation, a script automating association, validation, and removal instead of relying on USB and Intune workflows.
- Architecture and comparison. Windows Autopilot Device Preparation vs Device Association vs Classic Autopilot: What Is the Difference? compares classic Autopilot, base device preparation, and preparation with device association, outlining what each can achieve pre-sign-in and their support boundaries.
Key takeaways:
- Device association embeds a tenant affinity marker into the device’s UEFI firmware, verified through hardware attestation and TPM-based validation.
- This enables device-targeted policy assignments, naming devices before enrollment, automatic corporate identification, and OOBE customizations unattainable through base device preparation.
- Support precedence is documented: if a device is unassociated, the Windows Autopilot profile prevails; if it is associated, the device association takes precedence, and the device preparation deployment will occur.
- Both solutions can coexist in one organization, yet any single device can only operate under one.
Explore the complete series if you:
- Are selecting a provisioning model for a new client and require a side-by-side view of support boundaries
- Assist customers on hybrid join, Windows 10, or pre-provisioned setups, all of which remain in Windows Autopilot’s domain
- Work with GCC High or DoD clients, where device preparation is permissible, but Windows Autopilot is not supported
Source: Rudy Ooms
Before quoting it: Currently, OEM and partner pre-association options are unavailable, necessitating human input for this part. Confirm the latest support boundaries via Microsoft Learn before structuring a provisioning design around them.
We aim to create a valuable blog and meetup series, so I encourage you to join the next session, subscribe to this blog, and leave any comments, questions, or suggestions for future topics below. Let us help you connect with experts, discover relevant topics, and gain insights that will assist in growing your business.
Share this content:
Discover more from Qureshi
Subscribe to get the latest posts sent to your email.