Welcome to September's newsletter.
As always, feel free to forward this newsletter to anyone you want, and if you got it from a friend, please subscribe and get your own.
This month we have a lot of changes and some interesting things. Most of them land in October, so I focused on what you can do before then.
There's also a technical section near the end, so feel free to skip it if that's not your thing.
So let's take a look at what's new.
Things to check before October ends
- Project Online retires on September 30, 2026. As I told you in last month's issue, after that date your projects, schedules and timesheets in Project Online are no longer accessible. Any Power Automate flow that uses Project Online also stops working. If you still have data there, export it today. The Project desktop app keeps working on its own. Microsoft Planner is Microsoft's suggested replacement (Microsoft's guide).
- Publisher leaves Microsoft 365 on October 1, 2026. If you use it through a Microsoft 365 subscription, you lose access on that date. If you bought it as a one-time purchase, it keeps working, but support ends on October 13, 2026. Convert the files you want to keep now: open each one and use File > Save As to save it as a PDF. You can then open the PDF in Word to keep editing (Microsoft's page).
- Office 2021 stops getting security updates on October 13, 2026. This includes Office Home & Student 2021 and Office Home & Business 2021. The apps keep working, but any new security problem found in Word, Excel or Outlook after that date won't be fixed. If you bought Office 2021 as a one-time purchase, plan your upgrade now. Not sure which version you have? Open Word and go to File > Account. Here's Microsoft's page with the details.
- Sharing files is changing. OneDrive and SharePoint get a new sharing experience between mid-September and late October 2026. Each file and folder gets one main link, which Microsoft calls the "hero link". The nice part is that you can change who the link works for after you send it. By default, it only works for "people added to the file". So if someone can't open your file, add them to the same link instead of sending a new one. Your old links keep working and show up under "Other links" (MC1454378).
- People outside your company may lose access to files you shared before. Until now, external people could open a file you shared by typing a one-time code sent to their email. Microsoft is retiring that option during October 2026, and expects to finish by October 31. External people now need a guest account in your company's directory. New shares create that account automatically, but older links don't. Anyone without a guest account gets "access denied". If you share files with clients or partners, share the important ones again, or ask your IT team to create guest accounts for those people (MC1243549).
Nice changes in Outlook and Teams
- The new Outlook can look like classic Outlook. If you moved to the new Outlook and miss the old look, there's a new "Outlook Classic" theme. It changes the layout, fonts and icons, but the features stay the same. Turn it on in Settings > General > Appearance. It's rolling out from late September to late October 2026, so give it a few weeks if you don't see it yet (MC1458476).
- You can report a suspicious meeting in Teams. A new "Report a meeting" option shows up in the More actions (...) menu during a meeting, and in the meeting chat header. Use it for phishing, someone pretending to be someone else, or anything that looks like a scam. Your report goes to your company's security team. It's on by default and reaches everyone starting in early October 2026 (MC1446794).
A phishing trick that uses a real Microsoft page
Last month I wrote about a phishing trick that hides in the reply button. Here's another one, and nothing in it looks fake.
In May 2026, the FBI warned about a phishing service called Kali365. Here's how it works:
- You get an email that looks like a normal file sharing notification.
- The email gives you a code and asks you to type it on a real Microsoft page.
- The page is legitimate, so everything looks fine. But the code signs in the attacker's device with your account.
The attacker gets into your Microsoft 365 account without your password. The extra check on your phone doesn't help either, because you're the one approving the sign-in.
The rule is simple. Never type a sign-in code that you didn't request yourself. A code is only safe when you started the sign-in on your own device. If you already typed a code from an email, tell your IT team right away.
Power Automate and SharePoint
- The Power Automate mobile app is gone. As I told you in the first issue, Microsoft removed the iOS and Android apps on August 31, 2026. Your flows keep running. But the "Send me a mobile notification" action no longer sends push notifications, and the home screen widget stopped working. Replace those notifications with an email or a Teams message. For approvals, use the Approvals app in Teams. To check or run flows on your phone, open the Power Automate portal in your phone's browser. Here's Microsoft's list of alternatives.
- SharePoint alerts are gone. Microsoft started turning them off in July 2026. If you used "Alert me" to get an email when something changed in a list or library, you need a replacement. For simple cases, like "email me when an item is added", create a rule from the list's Automate menu. For anything else, use Power Automate. I recently wrote about triggering a flow when something changes in SharePoint, including how to show the value before and after the change. That's more than the old alerts ever gave you (Microsoft's page).
- An update on something from the first issue. I told you that restoring deleted flows yourself was planned for July 2026. As of September 1, 2026, it's no longer in Microsoft's list of planned features. I don't know if it moved or was cut, so I'll tell you when I see it ship. Until then, export your important flows so you have a copy.
- AI Builder credits end on November 1, 2026. A quick reminder from last month. AI Builder is what powers things like reading invoices or extracting text in your flows. After that date, new premium licenses stop including AI Builder credits, and nothing converts to Copilot Credits automatically. The credits you already have last until your contract ends. If your flows use AI Builder, talk to whoever handles your licenses (details).
For your IT team (technical)
This part is technical. Skip it if it's not your area, or forward it to whoever manages Microsoft 365 and the Power Platform in your company.
- The next big Power Platform update arrives over the next few weekends. As I shared in last month's issue, twice a year Microsoft pushes a mandatory update, called a release wave, to every Power Platform environment. It can't be postponed, and it lands over a weekend that depends on your region. The UK, Japan, Singapore, Sweden and Asia Pacific get it on October 2 to 5, 2026. Europe gets it on October 9 to 12, and North America and Australia on October 16 to 19. Plan a quick check of your most important apps and flows on the Monday after your weekend (calendar).
- Exchange Web Services (EWS) starts shutting down in October 2026. EWS is an old way for apps and scripts to read mailboxes and calendars in Exchange Online. Microsoft starts disabling it for all organizations in October 2026, and turns it off completely in April 2027. Start with the EWS usage report in the Microsoft 365 admin center to find what still depends on it. Then move those apps to Microsoft Graph, or ask your vendors when they will (Microsoft's page).
- Basic authentication for SMTP AUTH gets disabled by default at the end of December 2026. SMTP AUTH is how devices and apps send email through Exchange Online with a username and password. Think of scanners with "scan to email", printers, or older apps. Admins can still turn it back on, and Microsoft will announce the final removal date in the second half of 2027. Use this time to move those devices to OAuth (timeline).
- Block device code sign-ins if you don't need them. This is the fix for the phishing trick above. The FBI recommends a Conditional Access policy that blocks device code flow for all users, with limited exceptions. Check who uses it today before you turn it on, and exclude your emergency access accounts so you don't lock yourself out (FBI announcement).
- Prepare guest accounts before the SharePoint one-time passcode retirement. Make sure Microsoft Entra allows guest invitations, and that email one-time passcode isn't disabled in the External ID settings. Then find your regular external collaborators without guest accounts and create them as soon as you can, since the retirement runs through October (MC1243549).
- Coding agents can now build canvas apps. Last month I told you about using GitHub Copilot CLI and Claude Code with the Power Platform. On September 1, 2026, Microsoft made the canvas authoring plugin generally available. It's in the same power-platform-skills repository. An agent can create screens, add controls and write Power Fx formulas in your Power Apps canvas app while you edit it too. Same advice as before. Test it outside production first (announcement).
- Patch your SharePoint servers. This is only for SharePoint Server, the version you install on your own servers. The August 11, 2026 security updates fixed several SharePoint Server vulnerabilities. Two of them are rated "Exploitation More Likely": CVE-2026-63520 and CVE-2026-70355 (Rapid7 summary).
Some updates to the site
The account system was launched. The account allows me to start preparing some cool tools and things to release on the website. You can already benefit from it by bookmarking articles and seeing your comments and interactions with me in a single place. More to come, but this is already a good start, in my opinion.
I've also added the IFTTT area. I forgot it existed and I wanted to revisit it, so I'll publish what I learn. It's been a while since I used it, so it will be a good way to try out another automation tool.
There are never too many automation tools :).
Random Stuff
- We know TL;DR but now we have AI;DR (AI; Didn't Read). AI is getting a bad rap, and it's deserved in certain places, but it's here to stay. Slop is getting out of hand, but there are interesting automations that you can do, so don't stick your head in the sand. Use it for what's good.
- Thinking in Python Book. I know that any of the frontier models (and not only those) can write code for you, but knowing how it works is super important, so take a look and learn a bit about Python in this great book (no affiliation, and it's free to read online). Anything that you do to learn is a good thing in my opinion, so learn more and don't delegate everything to AI.
- Fake CAPTCHA scams. We are all tired of these CAPTCHAs, but bots are so aggressive that if you don't add them to your website, your site can't do anything. But be careful, because there are some sneaky people trying to install malware on your computer.
See you all in one month!
Photo by Ross Sneddon on Unsplash
No comments yet
Be the first to share your thoughts on this article!