
If your business runs on Microsoft 365, every login goes through a Microsoft service called Entra. It is the part that decides who your staff are and what they are allowed to open. Most owners never see it, but it quietly controls access to your email, files and finance systems.
Microsoft has just released a batch of updates to it. According to 4sysops, the September 2026 changes cover tenant governance, access reviews aimed at the person rather than the system, lifecycle workflows for staff joining and leaving, passwordless identities for Teams devices, hybrid identity provisioning, and controls over AI traffic. Some are fully released and some are still in preview.
The part worth flagging is the warning attached to it: there are three further changes coming that affect dynamic group rules, API permissions and the Security Administrator role. Those are the settings that decide who lands in which access group, what third-party apps are allowed to do with your data, and who holds the keys to your security settings. If nobody is watching, a change there can quietly widen access or break a workflow you rely on.
You do not need to follow Microsoft’s release notes to stay on top of this. Two practical habits cover most of the risk:
- Review who still has access. Former staff, old contractors and long-forgotten shared accounts are the most common way an ex-employee still reads company email. Access reviews exist precisely because this drifts.
- Check what your apps can do. Every app someone connects to your Microsoft 365 account carries permissions. Those permissions rarely get revisited after the day they were approved.
None of this is an emergency, and there is no breach here. It is ordinary housekeeping that pays off on the day someone leaves on bad terms, or an app you forgot about turns out to have more access than it needed.
Worried this affects your business? Get a free 15-minute IT check – call Trends IT on 0485 011 911 or visit /contact/.
