Basic authentication retired in Exchange Online
31 Mar 2026
Basic authentication is gone from Exchange Online. Anything presenting a plain username and password to a mail endpoint no longer connects. The visible failures happened immediately, but the quiet ones are still being found: scheduled scripts, multifunction printers scanning to email, monitoring agents, and service accounts nobody had documented.
What to check
- check_box_outline_blankSearch your scheduled tasks and automation servers for stored mail credentials.
- check_box_outline_blankCheck every multifunction printer and scanner configured to send email.
- check_box_outline_blankReview service accounts that authenticate to Exchange but have no owner recorded.
- check_box_outline_blankConfirm monitoring and alerting agents moved to OAuth rather than being silently disabled.
Source: Microsoft Exchange Team blog
Secure Boot 2011 certificates begin expiring
27 Jun 2026
The Microsoft Corporation KEK CA 2011, Windows Production PCA 2011 and UEFI CA 2011 certificates expire in stages between June and October 2026. This affects physical and virtual machines across Windows 10, Windows 11 and Windows Server from 2012 onwards, including LTSC. Machines already carrying the 2011 UEFI CA continue to boot. What is lost is the ability to trust newly signed binaries and to apply future Secure Boot updates, which is a failure with no symptom until an audit finds it.
What to check
- check_box_outline_blankReport on which devices already carry the 2023 certificates. Most hardware built since 2024 does.
- check_box_outline_blankIdentify devices that cannot receive them through the normal update path: restricted rings, offline machines, vendor controlled appliances.
- check_box_outline_blankCheck virtual machine firmware templates that were built once and cloned since.
- check_box_outline_blankCross reference against the Windows 10 replacement list. A device being retired first does not need this work.
Source: Windows IT Pro blog
Exchange Web Services disabled by default
1 Oct 2026
Phased disablement begins. Tenants that did not explicitly opt out have EWSEnabled set to false. Administrators can still re-enable it and approve named applications through an AppID allow list, so this is a hard stop with an escape hatch. That escape hatch closes permanently in April 2027.
What to check
- check_box_outline_blankPull the EWS usage report from the Microsoft 365 admin centre and sort by application ID.
- check_box_outline_blankName an owner for every calling application, including ones bought by facilities or finance.
- check_box_outline_blankCheck room and desk booking panels specifically. They authenticate to your tenant and appear on no IT inventory.
- check_box_outline_blankGet every vendor's Graph migration position in writing, with a date.
- check_box_outline_blankIf you set the allow list, record it as a dated exception with a review, not a resolution.
Read the full post: EWS goes dark in October, and your migration tool probably still uses itarrow_forward
Source: Microsoft Exchange Team blog
Windows 10 consumer ESU ends
13 Oct 2026
Windows 10 left standard support in October 2025. Consumer Extended Security Updates end here. Enterprise and education customers can continue to purchase ESU on a yearly basis for up to three years, taking coverage to October 2028.
What to check
- check_box_outline_blankSeparate devices that need replacing from devices that can be upgraded in place.
- check_box_outline_blankAttach every ESU renewal to a dated reduction in the number of devices needing it.
- check_box_outline_blankIdentify applications with no supported Windows 11 version and assign an owner to each vendor conversation.
- check_box_outline_blankWork backwards from October 2028 by eighteen months. That earlier date is your real deadline.
Read the full post: Windows 10 ESU is a bridge, not a planarrow_forward
Source: Microsoft Windows ESU
Exchange Web Services permanently retired
1 Apr 2027
Final retirement. The allow list mechanism is withdrawn along with the protocol. Migration to Microsoft Graph is not a protocol swap: Graph uses a different permission model, and applications that relied on broad impersonation across mailboxes need scoped application permissions and the approvals that come with them.
What to check
- check_box_outline_blankTreat the six months from October as execution time, not decision time.
- check_box_outline_blankBudget for the security review that Graph application permissions will require.
- check_box_outline_blankReplace any vendor who cannot state a Graph migration date.
- check_box_outline_blankTest Graph based migration paths before you need them for a live cutover.
Read the full post: EWS goes dark in October, and your migration tool probably still uses itarrow_forward
Source: Microsoft Exchange Team blog
Windows 10 enterprise ESU ends for good
Oct 2028
The last year of the enterprise Extended Security Updates programme. After this there is no supported path that keeps Windows 10 patched. Fleets still running it are unsupported, which for most regulated environments is a compliance position rather than a technical one.
What to check
- check_box_outline_blankCount the devices that physically cannot run Windows 11 and treat that as a capital plan, not an IT ticket.
- check_box_outline_blankStart procurement early. The last six months is when every other organisation reaches the same supplier.
- check_box_outline_blankIdentify the machines that must not be disturbed and give each one a named owner now.
Read the full post: Windows 10 ESU is a bridge, not a planarrow_forward
Source: Microsoft Windows ESU