The Microsoft 365 roadmap for September 2026 emphasizes anchoring Copilot responses in business data and associated compliance mechanisms. Microsoft 365 administrators should primarily evaluate new reference types, the expansion of data loss prevention, and delegated governance functions.

Microsoft 365 priorities to follow in September 2026
The announced changes converge toward the same objective: making Microsoft 365 Copilot usage more actionable at the organizational scale, without separating user experience from security and compliance requirements.
Three initiatives must be prioritized:
- controlling the sources that can enrich Copilot Notebooks responses;
- verifying that Microsoft Purview policies cover the relevant Outlook clients;
- designating functional owners for prompts, agents, and organizational data.
A roadmap is not a deployment schedule
Items marked GA/Preview or GA/TR in the roadmap may be offered according to the tenant, channel, or region. Validate each availability in the Microsoft 365 admin center and evaluate it in a pilot environment before any internal communication.
Feature identifiers constitute a useful control point when consulting the Microsoft roadmap. They enable distinguishing near announcements, previews, and items whose deployment remains progressive.
Copilot Notebooks extends reference data
Copilot Notebooks will receive three additional reference formats: Power BI reports with feature 569928, CSV and TSV files with 569210, then JPG and PNG images with 569211.
This extension changes the nature of data that can be used to generate a summary, scoping note, or presentation. A Power BI report brings aggregated business data. A CSV or TSV exposes structured data. An image can contain visual or text elements useful to the requested context.
Before opening these uses, the IT team must verify:
- access permissions to Power BI reports and source files;
- possible presence of sensitive data in CSV or TSV exports;
- confidentiality labels and sharing rules applied to files;
- guidance given to users on images containing confidential information.
The expected benefit is better anchoring of responses in the provided context. This does not exempt a human review. A notebook can leverage an authorized reference while producing an imprecise or incomplete interpretation.
Copilot Studio strengthens agent evaluation and sharing
Three changes concern Copilot Studio: modernizing agent evaluations (569607), sharing agents between makers (569475), and configuring conversational connectors (569930).
Evaluations provide more readable reasoning traces, dataset generation, and execution comparison. These capabilities are useful for industrializing tests before publishing an agent. They should be integrated into a testing process with nominal scenarios, edge cases, and requests containing sensitive information.
Sharing between makers simplifies collaboration but also broadens the number of people who can contribute to an agent. An organization must therefore define who can create, modify, validate, and publish an agent. Technical delegation does not replace business responsibility for responses and knowledge sources.
Purview brings Copilot closer to compliance requirements
Feature 569612 introduces retention for Copilot Memory in Microsoft Purview. Memory items are stored in Exchange and can thus enter a retention scope, versioning, and historical visibility.
This change involves reviewing existing retention policies. The key point is not just the retention duration. It is also necessary to decide which roles will be able to search, examine, or administer these contents as part of compliance procedures.
Feature 568785 adds explicit lifecycle state assessment controls in Adaptive Scopes. It aims for more precise targeting of Purview policies. Compliance teams should test the resulting populations before replacing an existing scope.
Outlook extends DLP controls on Mac and mobile
Three changes are expected for data loss prevention, or DLP: DLP Wait-on-Send for Mac (569719), DLP Wait-on-Send for mobile (569718), and DLP for Calendar Events on Mac (569717).
The objective is to improve the consistency of protections across Outlook platforms. Policies already designed for Windows or web use must nevertheless be validated with real scenarios on macOS and mobile devices.
Test DLP by platform
Prepare a set of messages and calendar invitations containing representative types of sensitive information. Verify triggering, alert text, send behavior, and logging for each Outlook client affected.
Microsoft Purview eDiscovery must also support SharePoint Embedded containers with feature 569364, particularly for Loop, Copilot Pages, and Notebooks. eDiscovery managers should confirm that their search and collection procedures adequately cover these new locations.
Teams, SharePoint, and Planner evolve on the experience side
In Microsoft Teams, feature 569207 allows users to report a security issue during or after a meeting. The operational value will depend on the processing circuit established. Security teams must define the reporting destination, the expected qualification level, and response timeframes.
Assignment and certification badges in Teams profile cards, feature 568078, improve identity readability. However, administrators must verify the quality of HR data or certification sources before presenting this information as reliable.
On the SharePoint side, Site Skills management with 570155 provides versioning, publishing, restoration, and duplication between sites. This capability calls for a governance model: designated owners, publishing rules, and procedures for retiring obsolete versions.
Comments anchored in PDFs, feature 569020, bring the PDF experience closer to that of Office documents. Site owners should anticipate the impact on document review practices and conservation of exchanges.
Finally, Planner adds Conditional Coloring (569476) and Connected Plans (569929). These functions improve reading priorities and navigation between linked plans. They mainly require clear conventions on the fields or conditions used to avoid producing visually incoherent dashboards.
Summary of functions and administrative impact
| Function | ID | Indicated Status | Priority Administrative Action |
|---|---|---|---|
| Power BI references in Copilot Notebooks | 569928 | GA/Preview | Verify access to reports and exposed data |
| CSV/TSV and JPG/PNG references | 569210 and 569211 | GA/Preview | Frame files and images admitted as sources |
| Copilot Studio evaluations and sharing | 569607 and 569475 | GA and GA/Preview | Formalize testing and maker roles |
| Copilot Memory retention | 569612 | GA | Review Exchange and Purview retention policies |
| DLP Outlook Mac and mobile | 569717, 569718 and 569719 | GA | Test policies on all targeted clients |
| eDiscovery SharePoint Embedded | 569364 | GA/Preview | Update search and collection procedures |
| Teams security reporting | 569207 | GA/TR | Define the response process for reports |
| Delegated prompt publishing | 569425 | GA | Assign delegation to responsible groups |
The GA/Preview and GA/TR mentions indicated in the roadmap must be verified before integrating them into a tenant-wide policy. General availability does not mean that all options will be enabled by default or that all licenses provide access to the same experience.
Governing prompts and organizational data
Feature 569425 allows delegating Copilot prompt publishing to users or groups. It addresses a frequent need: enabling business teams to contribute to a prompt library without assigning them global administration privileges.
This delegation must be accompanied by simple rules: an identified owner, review before publishing, a review date, and a withdrawal mechanism. Shared prompts can influence work practices at scale. They therefore deserve the same level of governance as internal knowledge content.
The Organizational Data Services profile data quality report, feature 568937, helps identify gaps affecting People Cards, Org Explorer, Copilot, and Cowork. Results should be entrusted to HR or organizational data owners. The Microsoft 365 team can diagnose quality but must not arbitrarily modify business attributes.
Preparation: Controls to perform before activation
Successful implementation relies less on activating each novelty than on the ability to measure its impact. The following sequence reduces the risk of inconsistent deployments.
Map new Copilot sources
Inventory Power BI reports, CSV or TSV exports, and image libraries that could be used in Copilot Notebooks. Identify their owner, sensitivity level, and sharing rules.
Validate Purview protections
Execute DLP tests on Outlook for Mac, mobile, and calendar. Also control the scope of Adaptive Scopes before modifying any existing compliance policy.
Update eDiscovery procedures
Add SharePoint Embedded, Loop, Copilot Pages, and Notebooks to document search scenarios. Verify operational roles and collection steps with the legal or compliance team.
Frame Copilot Studio contributors
Create a validation circuit for published agents and prompts. Limit publishing delegation to groups with explicit responsibility for content and usage.
In summary: Actions to launch Monday morning
Start by examining Copilot Notebooks novelties and their potential exposure to Power BI, CSV, TSV, and image data. Then, plan a DLP testing campaign on Outlook for Mac and mobile, as these changes directly affect send behaviors.
Update retention policies for Copilot Memory and eDiscovery procedures for SharePoint Embedded. Finally, clearly assign governance of agents, delegated prompts, and profile data.
If the organization is deploying Copilot at scale, prioritize a pilot combining security, compliance, HR, and business teams. The functions of September 2026 bring most value when data, roles, and controls are prepared before their availability.



