SPFx 1.24 Beta 3 Brings React 18 and Opens Copilot Components to Everyone
The most consequential developer news this week is the August 2026 SharePoint Framework roadmap update, which ships SPFx 1.24 Beta 3 and confirms that React 18 support is landing in the 1.24 release. That is a long-awaited jump for anyone building custom web parts and extensions, because it finally aligns SPFx with the React version most modern component libraries and tooling already target. Teams that have been holding back custom development to avoid rewriting against an older React should treat this as the signal to start planning the upgrade path.
The bigger strategic item is that the Copilot Components public preview — the capability first announced in June as SharePoint Copilot Apps — is now open to everyone, with general availability targeted for October 2026. Copilot Components let developers build AI-driven experiences that sit on top of real business processes rather than bolting a chat box onto a page. Microsoft is also opening a hands-on preview program where its engineering and product teams work directly with customers to build agents on top of these components, which is a rare chance to shape the model before it hardens.
For an organization thinking deliberately about how to introduce AI, this is where the shape of your Copilot footprint gets decided. A Copilot Component built against a clean, well-modeled business process becomes a reliable, reusable asset; one built against a messy list or an undocumented workflow becomes technical debt with an AI label on it. The preview window is the cheap moment to get the underlying process right.
What to do: Have your development team spin up SPFx 1.24 Beta 3 in a non-production tenant to validate your existing custom web parts against React 18, and identify one well-understood business process to prototype as a Copilot Component during the preview rather than waiting for October general availability.
Viva Connections Multi-Home Management Moves Into the SharePoint Admin Center
Administrators get a meaningful consolidation this month: Viva Connections multi-home site management is moving out of the Microsoft 365 admin center and into the SharePoint admin center. From the new location, admins can create and manage multiple Home sites, configure audience targeting, set home site priority order, and remove Home sites — all in one place. The existing entry points in the Microsoft 365 admin center will redirect administrators to the new SharePoint admin center experience.
This continues a clear pattern of Microsoft pulling SharePoint-adjacent governance and configuration back into a single console. For large organizations that run multiple intranet home sites targeted at different regions or divisions, having creation, targeting, and priority ordering in the same tool that already manages the underlying sites removes a genuine source of confusion — no more bouncing between two admin centers to reason about which audience sees which home experience.
The practical caution is that a moved setting is an easy setting to lose track of. Documentation, runbooks, and any internal training that points admins at the Microsoft 365 admin center for Viva Connections home site work is now out of date, and a redirect is a poor substitute for knowing where the control actually lives.
What to do: Update your admin runbooks and internal documentation to point at the SharePoint admin center for Viva Connections home site management, and while you are in there, review your home site priority order and audience targeting to confirm the right groups are seeing the right intranet experience.
Governance Tightens: A New Permissions Report and Auto-Labeling at Scale
Two governance changes this week are worth admins' attention together, because both are about seeing and controlling where data goes. First, a new Permissions Report has been added to the SharePoint admin center under Data Access Governance, surfacing which sites a given user can access — including both direct and group-based permissions — in a single view. Answering "what can this person actually get to?" has historically meant stitching together site collections, group memberships, and sharing links by hand; a first-class report that resolves both direct and inherited access is exactly the kind of tooling that makes an access review feasible instead of aspirational.
Second, auto-labeling for SharePoint and OneDrive is scaling up dramatically, moving from a ceiling of roughly 100,000 files per day to 500,000 files per day. For organizations that have been slow-rolling sensitivity labels because the throughput could not keep pace with their content volume, that five-fold increase changes the math on how quickly a tenant can reach broad label coverage. Faster labeling also means faster enforcement of whatever protection and DLP policies ride on those labels, so the labels themselves need to be right before the volume ramps.
The connecting thread is that Microsoft keeps handing admins better instruments for data access governance, but the instruments only help if the underlying policy is sound. A permissions report is only as useful as your willingness to act on over-permissioned sites, and higher auto-labeling throughput only helps if your label taxonomy and auto-labeling rules are actually calibrated to your data.
What to do: Run the new Data Access Governance permissions report against a few sensitive sites and your highest-privilege users to catch over-broad access, and review your auto-labeling policies and label taxonomy now — before the higher 500,000 files/day throughput accelerates enforcement across your tenant.
Multi-Tenant Agent Management Reaches Public Preview
Enterprises and partners running more than one Microsoft 365 tenant get a new control point this month: multi-tenant agent management in the Microsoft 365 admin center has begun rolling out in public preview, letting admins centrally view and manage Copilot agents across connected tenants. As agents proliferate across SharePoint, Copilot, and the broader Microsoft 365 surface, the ability to inventory and govern them from a single pane — rather than logging into each tenant separately — becomes essential for anyone operating at scale or managing customers.
This matters because agent sprawl is the next governance frontier. It is easy to stand up agents faster than anyone is tracking them, and an agent that quietly has access to sensitive SharePoint content is exactly the kind of thing that should show up in a central inventory rather than being discovered during an incident. A cross-tenant management view is the prerequisite for treating agents as governed assets instead of one-off experiments.
For consultancies and managed service providers, centralized cross-tenant agent visibility is also a service-delivery unlock, making it realistic to apply consistent standards and review cadences across every client environment from one place.
What to do: If you operate or manage multiple tenants, enroll in the multi-tenant agent management public preview and start building a simple inventory of which Copilot agents exist where, who owns them, and what content each can reach — the same way you would track any other privileged integration.
Retirement Watch: Keep the 2026 Cutoffs on the Calendar
With so much new capability arriving, it is easy to lose track of the retirements still working through the 2026 calendar, several of which are hard cutoffs rather than soft deprecations. The SharePoint One-Time Passcode (OTP) external authentication method begins its production retirement on October 1, 2026 and completes across environments by the end of the month, with external sharing moving to Microsoft Entra B2B guest accounts. Existing OTP-based sharing links will start failing at the start of October, so the window to provision B2B guests for active external partners is now narrow.
Earlier in the year, Microsoft permanently retired the SharePoint Add-in model and Azure Access Control Service (ACS) in April, and legacy IDCRL authentication was fully retired on May 1. Legacy compliance features — Information Management Policies, In-Place Records Management, and document deletion policies — have been retiring in favor of Microsoft Purview Data Lifecycle Management and Records Management, and SharePoint Alerts reached retirement in July. Each of these has a migration path, but the paths take planning, and the ones with October deadlines are the ones to move on now.
What to do: Before October 1, audit external sharing for links that still depend on SPO OTP and pre-provision Entra B2B guest accounts for the partners you actively collaborate with, and confirm any remaining reliance on retired Add-ins, ACS, or legacy compliance features has a completed migration rather than an open ticket.
Sources
- What's New in Copilot in SharePoint: August 2026 — Microsoft Community Hub
- SharePoint Framework (SPFx) roadmap update – August 2026 — Microsoft 365 Developer Blog
- Microsoft 365 Roadmap Updates August 2026 — Level Up M365
- Viva Connections Multi-Home Management Moves to SharePoint Admin Center in August 2026 — Windows Forum
- Microsoft Introduces New SharePoint Experience — AdminDroid Blog
- SharePoint Admin Center: Complete Guide for 2026 — SPS
- Microsoft SharePoint One-Time Passcodes Are Retiring: What To Do Next — ChangePilot
- SharePoint Add-In retirement in Microsoft 365 — Microsoft Learn
- Legacy SharePoint Authentication (IDCRL) Is Retiring — Microsoft Community Hub
- 2026 End-of-Support Milestone in Microsoft 365 — AdminDroid Blog