Stay ahead this August with 30+ Microsoft 365 changes, including feature rollouts, retirements, functionality changes, and other key updates for IT admins. In the Spotlight: Cross-Tenant Message Recall in Exchange Online: Exchange Online allows users to recall emails sent to external tenants that have added their organization to an allowlist. Security Detection Report in TAC: The new Security Detection Report enables administrators to monitor impersonation attempts, malicious URLs, and weaponizable files to improve threat visibility. Account Discovery in Entra: The new Account Discovery feature helps organizations detect unmanaged application accounts and link them to Microsoft Entra ID identities for improved governance and security. Here’s a quick overview of what’s coming: Retirements: 6 New Features: 8 Enhancements: 4 Functionality Changes: 4 Action Required: 5 Live Now: 1 Retirements: Starting Aug 3, 2026, Microsoft will block new assignments to the Partner Tier 1 and Tier 2 Support roles, which allow Microsoft partners to provide delegated support for customer tenants. Outlook is retiring the legacy Meeting Insights feature by Aug 2026 and replacing it with Copilot's "Prepare for this meeting" experience. Microsoft is officially retiring the Outlook for Windows report in the Exchange admin center this August. Effective Aug 15, 2026, the OneDrive sync app will stop receiving security patches, bug fixes, and feature updates on Windows 10 version 21H2 or older. As the standalone Whiteboard app reaches end of support , starting Aug 22 users will no longer be able to create or edit Whiteboards. Microsoft is retiring the Teams CAPTCHA meeting policy in late Aug 2026, replacing join verification checks with default-on automated bot detection. New Features: OneDrive on Windows and Mac will now let users & admins exclude specific folders from cloud syncing to keep sensitive or large data strictly local. Microsoft Purview will introduce an archive option to move inactive OneDrive and SharePoint files to M365 Archive to lower storage costs. Teams Rooms Pro on Android will support attending webinars & structured meetings as attendees , featuring interactive tools like chat, reactions, and live captions. Global Readers and Security Readers will soon gain view-only access to role assignments and scopes across Microsoft Purview and Defender. Organizations can now access Teams audit records for their own users in cross-tenant meetings without exposing cross-tenant participant data. Microsoft Teams adds support for linking meetings to existing Planner plans to manage all project tasks in one place. Microsoft Entra ID is updating passkey registration across My Sign-Ins, Authentication Strengths, and Registration Campaigns to automatically enforce admin policies and prioritize local device passkeys. Microsoft Purview now supports time-limited role group assignments, so admins can set temporary access expirations between 1 day and 2 years to enforce least privilege. Enhancements: Microsoft Teams is extending custom recording and transcription notifications to 1:1 calls , automatically applying existing meeting policies to one-on-one desktop conversations. Entra now extends Microsoft Purview sensitivity labels directly to cloud security groups to simplify group governance and policy management. Microsoft Purview now reduces DLP policy sync from 2 hours to 30 minutes for faster tenant-wide enforcement. Microsoft Teams now lets users add Planner tabs directly to Shared and Private channels for seamless task management across restricted and cross-organization workspaces Existing Functionality Changes: A new opt-in Safe Attachments policy in Defender for Office 365 automatically quarantines unscannable password-protected files like ZIP, RAR, PDF, and Office documents. Microsoft Entra ID now blocks cross-domain sign-ins by default whenever internal federation and UPN domains don't match. Microsoft Forms is transitioning automated notification emails to [email protected] , so admins should update email filtering rules and safe sender lists to prevent delivery issues. SharePoint Embedded will update driveItem.webUrl to return browser launch URLs starting mid-August 2026; switch to driveItemId for stable file tracking or opt out by Aug 17. Action Required: Starting Aug 2026, Microsoft will deprecate Teams Android device management in the Teams admin center as features move fully to the Pro Management portal. From Aug 1, Exchange Online deprecates TLS 1.0/1.1 for POP3 and IMAP4 , so admins should upgrade connections to TLS 1.2 or higher. With standalone MDTI retiring on Aug 1, organizations must migrate to Microsoft Defender or Sentinel licenses to retain threat intelligence capabilities. Admins must migrate Personal Bookings management to OWA Mailbox Policy settings before Aug 5, 2026, when legacy EWS controls are retired. On Aug 20, 2026, Microsoft 365 will permanently delete unresolved agent requests created before June 1, 2026 , unless admins approve or reject them beforehand. Live: Microsoft Entra Cloud Sync now supports device sync to align Active Directory computer objects for Entra hybrid joins in preview. submitted by /u/Shan_1130 [link] [comments]
The cross-site community pulse: gold-layer posts + comment threads read live from the Communication Hub, ranked by importance. Turn a post into Discord / LinkedIn / X.
Azure Weekly Highlights #30
by groovy-sky
Azure shipped another generous batch of updates this week—because apparently cloud platforms never sleep. Expect new networking and Kubernetes capabilities, AI-related additions, a new India region, plus a few previews for those who enjoy testing tomorrow’s features today. Full list: * [In preview] Public Preview: Azure Enclave(https://azure.microsoft.com/updates?id=568377). This feature is currently being tested and is available for early adopters. * [Launched] Generally Available: NAT64 on StandardV2 NAT Gateway(https://azure.microsoft.com/updates?id=568409). This update brings IPv6 support to the StandardV2 NAT Gateway. * [Launched] Generally Available: Application Routing with Gateway API(https://azure.microsoft.com/updates?id=567944). This new feature simplifies application routing within Azure. * [Launched] Generally Available: Resource placement in Azure Kubernetes Fleet Manager(https://azure.microsoft.com/updates?id=567931). This update helps manage where your Kubernetes resources are placed. * [In preview] Public Preview: Maximum allowed failures for update runs in Azure Kubernetes Fleet Manager(https://azure.microsoft.com/updates?id=567939). This preview allows you to set limits on update failures in Kubernetes. * [In preview] Public Preview: Prepared Image Specification(https://azure.microsoft.com/updates?id=567949). This specification is being tested for future image handling in Azure. * [Launched] Generally Available: Microsoft Azure now available from new cloud region in India (India South Central)(https://azure.microsoft.com/updates?id=568013). Azure is now available in a new region in India. * [Launched] Generally Available: Claude Opus 5 on Azure Databricks(https://azure.microsoft.com/updates?id=568316). This brings the powerful Claude Opus 5 model to Databricks. * [Launched] Generally Available: HTTP header insertion in Azure Firewall(https://azure.microsoft.com/updates?id=568115). This update allows for the insertion of custom HTTP headers in the firewall. * [In preview] Public Preview: AI Gateway in Azure API Management(https://azure.microsoft.com/updates?id=568184). This preview introduces AI capabilities to API Management.* [In preview] Public Preview: Azure Enclave(https://azure.microsoft.com/updates?id=568377). This feature is currently being tested and is available for early adopters. * [Launched] Generally Available: NAT64 on StandardV2 NAT Gateway(https://azure.microsoft.com/updates?id=568409). This update brings IPv6 support to the StandardV2 NAT Gateway. * [Launched] Generally Available: Application Routing with Gateway API(https://azure.microsoft.com/updates?id=567944). This new feature simplifies application routing within Azure. * [Launched] Generally Available: Resource placement in Azure Kubernetes Fleet Manager(https://azure.microsoft.com/updates?id=567931). This update helps manage where your Kubernetes resources are placed. * [In preview] Public Preview: Maximum allowed failures for update runs in Azure Kubernetes Fleet Manager(https://azure.microsoft.com/updates?id=567939). This preview allows you to set limits on update failures in Kubernetes. * [In preview] Public Preview: Prepared Image Specification(https://azure.microsoft.com/updates?id=567949). This specification is being tested for future image handling in Azure. * [Launched] Generally Available: Microsoft Azure now available from new cloud region in India (India South Central)(https://azure.microsoft.com/updates?id=568013). Azure is now available in a new region in India. * [Launched] Generally Available: Claude Opus 5 on Azure Databricks(https://azure.microsoft.com/updates?id=568316). This brings the powerful Claude Opus 5 model to Databricks. * [Launched] Generally Available: HTTP header insertion in Azure Firewall(https://azure.microsoft.com/updates?id=568115). This update allows for the insertion of custom HTTP headers in the firewall. * [In preview] Public Preview: AI Gateway in Azure API Management(https://azure.microsoft.com/updates?id=568184). This preview introduces AI capabilities to API Management. submitted by /u/groovy-sky [link] [comments]
Azure AI Foundry: GPT-4o to GPT-5.1 migration changed our RAG agent’s response style
by IncreaseLocal2574
Hi everyone, my team is migrating a production RAG agent from GPT-4o to GPT-5.1 in Azure AI Foundry because our GPT-4o version is approaching retirement. GPT-4o currently gives us concise, conversational, well-grounded answers. We tested GPT-5.1 with the same system prompt, knowledge base, RAG pipeline, and agent configuration, but the behavior is significantly different. GPT-5.1 produces much longer and more structured answers, often adds headings and summaries, and sometimes uses tables even though our system prompt explicitly forbids them unless requested. The answers are generally correct, but the response style is much less suitable for our users. Has anyone experienced the same issue when moving from GPT-4o to GPT-5.1? Did you solve it through: a redesigned system prompt; few-shot examples; verbosity or reasoning parameters; an output validator; a second rewriting pass; structured outputs; a regression test set based on previous GPT-4o responses? We do not expect identical outputs, but we would like to preserve GPT-4o’s concision, natural tone, lack of unnecessary tables, and grounding in the retrieved context. I would be very interested in hearing about real production migrations and what worked for you. submitted by /u/IncreaseLocal2574 [link] [comments]
Where do you store code for one off tasks that might be useful later on?
by VirtualAgentsAreDumb
I've been a developer for a few decades now, almost always in a DevOps kind of role, and every once in a while I have stumbled over this issue and never found a solution that sits well with me. As a DevOps guy, I both write and maintain the code, as well as being partly responsible for the operations and the data of the system. In our case the core of the system is a CMS, but it could be a DMS, CRM, IAM etc etc. And on occation we have a need to do some bulk operation on the data, in a way that has not been done before, and can't be done easily using some UI. If there will be a repeated need for that kind of bulk job then we will likely integrate it fully into the code, and have a user friendly interface for it. But what about more one off kind of tasks? Tasks that require coding, but that likely won't be needed again in the foreseeable future. The last time it happened to me, this was roughly the task at hand: Identify all objects in the system with properties X, Y and (Z1 or Z2) within section S1. Move them all from section S1 to section S2. For each object, update property X to a calculated new value. It is possible to do this manually in the regular GUI for the CMS. But that's not feasable when there are several hundreds of objects matching the criteria. Especially not when it's fairly trivial to write code that does the bulk job. But after the job has been run (first in dev/test/stage, and then in production), what should happen with that code? Just deleting it feels wrong, since it can be useful for some developer in the future. But letting it live among the regular code of the project seems odd to. Not only am I not sure where exactly in the code base it should live, but in what form? An own class with a main method that does this? Or in a method that has no code pointing to it? Or commented out? Or it could live in some Wiki, I guess. But unless the people involved in the project uses the wiki often, code snippets there are likely to be forgotten about the next time some bulk job needs to be done. I have seen various documentation projects shrivel up and die after a few months because people don't work in them regularly and then tend to forget they even exist. How do you guys handle this? In my case, the code usually ended up in a text file on my own computer, since it has involving project with me as the main developer and the guy who did all these kind of tasks. But it doesn't seem very future proof. submitted by /u/VirtualAgentsAreDumb [link] [comments]
Roadmap for low latency system engineer
by monitor1413
Cs grad (fresher) from tier 3 college, got a role at a reputed hft but not so good, want to switch to a system engineer role in about 1.5-2 yrs but couldn't decide if they prefer iit grads. If there is a chance then what's the best material available online. Also have experience of backend engineering. Prev posted to systems engineering sub, was told this sub is better for the above query submitted by /u/monitor1413 [link] [comments]
Stuck in an M365 loop. An external admin set my B2B guest account to "Block sign-in" (I no longer work with them). The organization is now a permanent zombie in my M365 profile backend. The Problem I cannot leave the organization myself Login fails instantly because my account is blocked Clearing browser data doesn't fix it; the entry just resyncs from the cloud My Question If I contact their IT: Is it enough if the external admin simply DELETES my guest object from their Entra ID? Will that automatically purge the tenant from my M365 profile backend? Or am I still required to manually "leave" on my end even after they delete me (which I cannot do)? I'm really not a fan of a foreign organization being connected to my tenant like this. Even if Microsoft claims it's secure ... who actually believes that? Nevertheless, that's IMHO a major design flaw. (Note: Since I am not a native speaker, I translated/polished this post with the help of an AI.) submitted by /u/anonRexus [link] [comments]
GCP Agent Platform stale models
by Limp-Iron
submitted by /u/Limp-Iron [link] [comments]
Just give a star if you think this is useful for you. I find it very useful and being using for a while to debug many issues when doing SRE. submitted by /u/shadydev99 [link] [comments]
Does OpenSearch Ingestion prevent OpenSearch Serverless (NextGen) from scaling to zero?
by FewJob1030
Hi Guys, I’m planning a setup with RDS for PostgreSQL as the source of truth and OpenSearch Serverless (NextGen) for search. Trying to decide whether to use an OpenSearch Ingestion pipeline to sync them, or just write to both from our own API layer. What I think I've figured out from the docs: - Ingestion OCUs (15 GiB + 2 vCPU) and Serverless OCUs (~6 GiB) are separate billing lines, no pooling between them. So, would I be charged for the OpenSearch OCUs, plus at least one additional OCU specifically for OpenSearch Ingestion. ( Could someone please confirm this? ) - OSI minimum is 1 OCU and there's no scale-to-zero, so a running pipeline is roughly €220/month regardless of throughput - NextGen removed the old 2-OCU floor, indexing and search scale independently, both drop to zero after 10 min idle What I can't figure out: Does an idle OSI pipeline keep the indexing OCUs alive? My reasoning says no, if the source DB has no changes, no bulk requests hit the collection, so after 10 minutes indexing should scale to zero. But I have no idea whether the pipeline sends background traffic (health checks, index existence checks, periodic no-op requests) that would reset the idle timer. Couldn't find this addressed anywhere. NextGen is only a couple of months old so there's not much out there yet. Thanks in advance to everyone who replies! submitted by /u/FewJob1030 [link] [comments]
If we already have Grafana, Datadog, Splunk, PagerDuty, etc., why are production incidents still so hard?
by No_Comfortable9746
I've been trying to understand what actually happens during production incidents, and something doesn't add up in my head. Let's say I'm on call and I get paged at 2 AM because "checkout is broken." We already have tools like Grafana, Datadog, Splunk, OpenTelemetry, PagerDuty, Kubernetes dashboards, cloud monitoring, CI/CD history, Git, runbooks... basically a ton of observability and operational tools. So where does the time actually go? Is it because the information is spread across too many places? Is it understanding what changed? Figuring out the blast radius? Knowing which team or dependency is actually responsible? Or is there something I'm completely missing? Reading incident postmortems, it feels like engineers already have lots of data, but they still spend a long time piecing together what actually happened before they can confidently act. For those of you who've been on call, what makes that first 15–30 minutes difficult, even with all these tools available? I'm genuinely trying to understand what I'm missing as a student because from the outside it feels like we already have a tool for everything, yet companies still spend hours resolving some incidents. submitted by /u/No_Comfortable9746 [link] [comments]
Anyone else annoyed that almost every helpdesk/ticketing tool bills per agent, even for internal IT/HR use?
by AwayLaw6220
Genuine question for the sub: for your internal helpdesk (IT, HR, facilities — not customer-facing support), are you still on a per-agent SaaS plan, and does that pricing model actually make sense for how you use it? We went through this recently. Most of the well-known ticketing tools charge per agent per month, which is fine for a customer support team justifying the spend against revenue, but feels off for an internal tool where "how many of our own employees can touch the ticket queue" shouldn't be the billing metric. It also means every time IT grows headcount, tooling cost grows with it — for a tool that isn't generating revenue. We ended up building/adopting something self-hosted that plugs into Entra ID (Azure AD) for SSO and directory sync, so new hires in the right AD group get access automatically and offboarding is one action in Azure AD instead of a separate step in a separate admin panel. Licensed per install, not per agent, so it doesn't get more expensive as the internal team grows. Not trying to turn this into a product post — mainly curious how others are handling internal ticketing cost/access, and whether per-agent pricing has ever actually been a blocker for you the way it was for us. Happy to share more details on what we built in the comments if useful, since it happens to be relevant here (full disclosure: I'm the one who built it). submitted by /u/AwayLaw6220 [link] [comments]
Hi everyone, I'm an MCA graduate (2025) from a Tier 3 college in Maharashtra(Pune). I had worked 1 yrs into Infrastructure Support before enrolling for masters. During my MCA, I also did 2 DevOps internships, and my goal has always been to build a career in DevOps. Since February, I've been applying for DevOps roles almost every day, tailoring my resume, working on my interview prep, and trying to improve my skills. Unfortunately, I haven't had much success so far, and it's honestly starting to feel a bit discouraging. My current skills include: \- Linux \- Networking \- AWS & Azure \- Terraform \- Docker \- Kubernetes \- Jenkins \- GitHub Actions \- Prometheus & Grafana At this point, I feel like I have two choices: \- Keep searching for a full-time DevOps role. \- Reach out to my previous employer and continue working in Infrastructure Support. What I'm really worried about is making the wrong decision. \- If I keep searching and still don't get a DevOps job after a few more months/years, what would you recommend? \- If I go back to Infrastructure Support, will it become much harder to switch into DevOps later? \- Has anyone here made the transition from Infrastructure Support to DevOps after a year or two? If yes, what helped you make that move? I'd really appreciate hearing from people who've been in a similar situation or anyone currently working in DevOps. Also if anyone has any opportunities for DevOps,SRE,Linux,cloud support or even NOC please help me out as I just want a start my career. Thanks! submitted by /u/PA1N-T_T [link] [comments]
Weekly Self Promotion Thread
by AutoModerator
Hey r/devops , welcome to our weekly self-promotion thread! Feel free to use this thread to promote any projects, ideas, or any repos you're wanting to share. Please keep in mind that we ask you to stay friendly, civil, and adhere to the subreddit rules! submitted by /u/AutoModerator [link] [comments]
Azure VM and Trusted Launch VM security advisory
by Administrative_Fan12
submitted by /u/Administrative_Fan12 [link] [comments]
How do you track Entra bypasses before they become permanent?
by Sad-oumemaEffort-725
We manage multiple Entra tenants for different clients. Common pattern: regional auth issues or MFA problems lead to temporary conditional access bypasses. Someone creates them under pressure, gives them a terrible name, and nobody ever looks at them again. Six months later the client's security team asks for a posture report. We are digging through policies that feel like archaeological layers of old incidents. Some are still needed. Some were workarounds for bugs that got fixed ages ago. Some nobody remembers at all. Do any of you keep a centralized register of these exceptions per client and review it on a schedule, or do you just deal with it when an audit forces the conversation? submitted by /u/Sad-oumemaEffort-725 [link] [comments]
Can I use AWS Bedrock this way?
by Oxffff0000
I haven't use AWS Bedrock. I just started hearing it last week from another team. They're also new to it. I would like to add a feature to a web application I wrote that displays logs. When there's an error, I usually google the error or nowadays, we paste it on copilot, claude or chatgpt. I'd like to add a button by the error log which when I click it, it will send the error log to an AI model in AWS Bedrock then respond back that I can display the solution on the webpage. Is that possible or am I missing a component? Thank you in advance! submitted by /u/Oxffff0000 [link] [comments]
Built a small internal billing tool for my own business. One user (me), barely any traffic. I keep landing around $18/month for hosting, which is more than I wanted, and I'm trying to figure out if I'm missing something obvious or if that's just what it costs? Not a professional developer so apologies if I use any terms wrong. It's a Node app with a React frontend and a Postgres database, runs in Docker. What I actually need: - Postgres where I can restore to a specific point in time, not just last night's backup. It tracks invoices and payments against Stripe, so if I restore a 24 hour old copy my records won't match what Stripe already charged people. That seems like a bad situation to be in. - Somewhere to store generated PDF receipts that doesn't get wiped. These are the actual documents I send customers and I can't just regenerate them later. Seems like a lot of the cheap container hosts have disks that disappear every deploy. - A cron job that runs once a day at a set time in my timezone. It's the billing run, so if it drifts to the wrong side of midnight it processes the wrong day. - Under $20/month. What I don't need: high availability, scaling, or speed. It's one person clicking around a few times a day. If it was down for a few hours nothing bad would happen. What I've already looked at: - Fly.io's managed Postgres is $38/mo on its own, way over budget - Railway's Postgres backups looked like snapshots only, no point in time restore - Supabase Pro is $25 and point in time restore is a $100/mo add-on - Cloud Run, App Runner, DO App Platform — filesystem doesn't stick around, kills the PDF requirement - Cheap VPS running everything myself is like $8, but then I'm responsible for making sure backups actually work, and honestly I'm not sure I'd notice if they quietly stopped Best I've come up with is Fly for the app (cheap if the machine sleeps when idle) plus DigitalOcean managed Postgres at $15, which includes 7 day point in time restore. Is there something cheaper that still lets me actually restore the database? Or is $15$20 ish just what managed Postgres costs and I should stop looking? submitted by /u/YetiWalker36 [link] [comments]
What do you wish existed when you started on a help desk?
by Same-Carry-2626
I’ve spent 10 years doing help desk/support work and I’m putting together a set of SOP templates, canned responses, and troubleshooting decision trees based on what actually comes up day to day — mostly for smaller teams or solo techs who don’t have this stuff written down anywhere. Before I finish it, I wanted to ask people who’ve actually been in the seat: what’s the thing that used to slow you down the most when you started? Or something you still wish was documented better where you work now? Not trying to sell anything here yet — genuinely want to make sure this is useful before I put more time into it. submitted by /u/Same-Carry-2626 [link] [comments]
Hello everyone, I'm looking for advice and guidance from those with more experience in the field. My Background: Experience: 3+ years in a Tier 1 Helpdesk/Support role. My scope is somewhat limited, primarily revolving around User Management, Identity and Access Management (IAM), Incident Management, and Splunk observability for banking payments. Education: Bachelor's degree in Accounting. Certifications: Basic Splunk certification. The Opportunity: I was recently offered a chance to volunteer as a SysAdmin for a non-profit, covering the following responsibilities: Manage and secure the organization’s Google Workspace environment (user accounts, permissions, and onboarding/offboarding processes). Provide technical support and troubleshooting for volunteers. Maintain clear technical documentation, onboarding guides, and self-service resources. Monitor system performance, security compliance, and cloud settings. Collaborate with leadership to evaluate tech needs, recommend software, and configure tools as the org scales. My Questions: Is this volunteer role worthwhile? Would combining my 3+ years of Tier 1 experience with a year of this SysAdmin volunteer work help me land a full-time SysAdmin role? Are there any specific certifications you would recommend I target next to round out my resume? Thanks in advance for your insights! submitted by /u/Spirited_Mud3171 [link] [comments]
Qualys Patch Managment
by threshforever
Hey everyone, not a sys admin but got tagged to work with my sys admin on the above. He’s a pretty smart guy and I want to not show up unprepared, I took some of the free sessions/classes that Qualys offers but lookin for any tips and tricks you might have. submitted by /u/threshforever [link] [comments]