Back to News
SharePoint OnlineSeptember 14, 2026

SharePoint Online Weekly Update — September 14, 2026

The FAQ web part splits into a plain-Markdown editor and a Copilot-driven authoring experience, Viva Connections multi-home site management moves into the SharePoint admin center, and a new item-level oversharing report gated behind a fresh admin role gives governance teams the file-level visibility they have been asking for.

The FAQ Web Part Splits Into a Manual Editor and a Copilot Author

The most concrete SharePoint-specific item on the roadmap this week is a quiet but telling change to the FAQ web part. Beginning in October 2026, the FAQ web part itself becomes a standard, non-AI experience for manually creating, editing, and managing frequently asked questions. The generative half of the feature — natural-language prompts and the ability to import and synthesize FAQ content from grounding sources — moves out of the web part and into the Copilot in SharePoint authoring experience, where authors generate content that is then saved back into a compatible FAQ web part. Existing FAQ web parts and their content keep rendering with no migration required.

This split is worth reading as a pattern rather than a one-off. Microsoft is separating the surface a reader sees from the authoring intelligence that produces it, and doing so on a component almost every intranet already uses. The web part stays simple and predictable; the AI lives in a dedicated authoring lane where prompts, grounding sources, and outputs can be governed and improved independently. It is the same architectural move behind the portable, evaluated skills Microsoft shipped earlier this month, now applied to a specific, familiar building block.

For organizations, the practical upshot is that "who can generate FAQ content with Copilot" and "who can edit the published FAQ" become two different questions with two different answers. That is a governance opportunity, not a complication — but only if you decide the answer deliberately rather than discovering later that anyone with a Copilot license has been auto-generating public-facing FAQ copy against whatever grounding sources happened to be handy.

What to do: Identify your highest-traffic FAQ web parts now, decide who should be allowed to author FAQ content through Copilot in SharePoint versus who merely edits the published component, and put a light review step between AI-generated FAQ drafts and publication before the October change lands.

Viva Connections Multi-Home Management Moves Into the SharePoint Admin Center

Administration for Viva Connections multi-home site management is moving out of the Microsoft 365 admin center and into the SharePoint admin center (SPAC), with rollout beginning early September 2026 and completing by mid-month. From SPAC, admins can create and manage multiple Home sites, configure audience targeting, set home site priority order, and remove Home sites — all in the same console where the rest of their site administration already lives. Existing entry points in the Microsoft 365 admin center will redirect to the new SPAC experience, and no pre-rollout action is required.

Riding along with the console move is a cleanup: legacy Viva Connections instances and the older draft-and-enable management model are being deprecated, and existing experiences are being upgraded to full Home sites. This consolidates what had become two overlapping concepts — "a Viva Connections experience" and "a SharePoint home site" — into one governed object. It is a sensible simplification, but it does mean the mental model and the documentation your admins have relied on are now out of date.

The change is administratively low-drama precisely because nothing breaks, which is also why it is easy to miss. The risk is not an outage; it is an admin spending twenty minutes hunting for a setting in the old location, or internal runbooks and training decks silently pointing at a console that no longer holds the controls.

What to do: Tell your SharePoint and Viva Connections admins that multi-home management now lives in the SharePoint admin center, and sweep any internal runbooks, onboarding docs, or training materials that still reference managing Viva Connections home sites from the Microsoft 365 admin center.

A New Item-Level Oversharing Report — Behind a New Admin Role

Governance teams get a meaningful upgrade this month: a new SharePoint admin center report that surfaces item-level visibility into content shared through the "Everyone" and "Everyone except external users" claims. Where admins previously could only see which sites contained these broad groups, the new report reveals the specific files and items exposed across SharePoint and OneDrive — and it does so without changing any existing permissions, so running it is a read-only diagnostic rather than a risky remediation. Output is downloadable as Excel or Power BI datasets, so it drops straight into the governance workflows most teams already run.

The detail that will trip organizations up is access. These file-level reports are gated behind a new SharePoint Advanced Management Administrator Entra role, part of the 2026 SAM expansion, and it is not granted automatically to Global Administrators or SharePoint Administrators. In other words, the people who most need this report may not be able to open it on day one, and someone has to consciously assign the role. Treat that as a feature: file-level oversharing data is exactly the kind of sensitive visibility that deserves its own scoped role rather than riding along with broad admin rights.

This matters more than usual right now because oversharing is the single biggest liability once Copilot is loose in a tenant. An AI assistant grounded in SharePoint will happily summarize and surface anything a user can technically reach, and "Everyone except external users" is the quiet default that turns a stray permission into an org-wide exposure. Finding those items before Copilot does is no longer a nice-to-have.

What to do: Assign the SharePoint Advanced Management Administrator role to a named, accountable owner, run the new oversharing report against your most sensitive sites, and prioritize remediating content exposed to "Everyone except external users" before broad Copilot grounding amplifies it.

OneDrive Absorbs SharePoint Library Views

Two OneDrive changes launched this week that are really SharePoint changes in disguise. First, users can now work with SharePoint document library views directly from OneDrive — switching between existing views and even creating and managing new ones — without leaving the OneDrive experience. Second, the old More places experience in OneDrive on the web is being replaced by a refreshed Libraries view that shows more recently accessed libraries, links to default document libraries for Teams and favorite SharePoint sites, and adds filtering, sorting, and view controls.

The through-line is that Microsoft continues to blur the seam between OneDrive and SharePoint document libraries, treating them as one content fabric that users navigate from whichever entry point is closest to hand. For end users this is pure convenience. For administrators, it is a reminder that the views, columns, and metadata you configure on SharePoint libraries now travel further than the SharePoint UI — a well-structured library pays off in more places, and a messy one is now messy in more places too.

There is also a subtle governance angle. As library views and content become reachable and customizable from more surfaces, the assumption that "users only see this library the way I set it up in SharePoint" weakens. Curated default views remain your best tool for steering people toward the right content, and they now do more work than before.

What to do: Audit the default views and metadata on your most-used document libraries, since they now surface through OneDrive as well as SharePoint, and treat clean, well-curated library structure as the foundation that makes every downstream surface — OneDrive, Teams, and Copilot alike — behave.

Purview Tightens Its Grip on SharePoint Content Lifecycle

The Microsoft Purview roadmap moved on several fronts this week that land squarely on SharePoint and OneDrive content. Coming in December 2026, Data Lifecycle Management will deliver insights and policy recommendations on sensitive SharePoint and OneDrive data, effectively telling admins where sensitive content lives and suggesting retention policies to govern it. Further out, into early 2027, Purview is building the ability to apply retention based on when a file was last accessed in SharePoint and OneDrive — a genuinely new lifecycle lever that lets cold, untouched content age out on its own schedule rather than by creation date alone. And a November 2026 capability will let admins delete both content and containers for departed users' OneDrives and mailboxes at scale.

Taken together with the storage-billing and archiving changes that arrived earlier this month, the direction is unmistakable: Microsoft is assembling a full economic and compliance toolkit around content lifecycle, where stale data now carries a metered cost and a growing set of automated ways to retire it. "Last accessed" retention in particular closes a long-standing gap — plenty of content is old by any reasonable measure yet looks fresh because it was created recently and never touched again.

For AI programs specifically, lifecycle discipline is not a compliance sidebar; it is grounding hygiene. Every stale, forgotten, or over-retained document is a candidate for a Copilot answer that cites something the organization would rather had quietly expired. The organizations getting ahead of this are treating retention and access-based cleanup as a prerequisite for trustworthy AI, not a task for a later quarter.

What to do: Map which of these Purview capabilities apply to your tenant and put the December sensitive-data insights and 2027 last-accessed retention items on your roadmap now, and start pruning stale SharePoint and OneDrive content so it never becomes a Copilot grounding liability.

Retirement Watch: The October 1 OTP Cutoff Is Now Days Away

With so much new capability arriving, the hard cutoffs still moving through the calendar are easy to lose track of — and the most urgent is now measured in days. The SharePoint One-Time Passcode (OTP) external authentication method begins its production retirement on October 1, 2026, completing across environments by month-end, with external sharing shifting to Microsoft Entra B2B guest accounts. Once OTP retires, external sharing links that depend on it will start failing, so the window to pre-provision B2B guests for the partners you actively collaborate with has effectively closed to a final sprint.

Longer-horizon items remain worth tracking. Microsoft is retiring all four standalone SharePoint Online and OneDrive for Business plans — no new sales after May 2026, no renewals after January 2027, full retirement by December 2029 — which affects any organization licensing SharePoint outside a Microsoft 365 suite. And earlier 2026 retirements, including the SharePoint Add-in model, Azure Access Control Service (ACS), and legacy IDCRL authentication, are already past their cutoffs; anything in your tenant still leaning on them is an open incident rather than a future planning item.

What to do: Before October 1, do a final audit of external sharing for links still relying on SPO OTP and pre-provision Entra B2B guests for active partners, confirm your licensing path if you hold any standalone SharePoint plans, and verify that reliance on retired Add-ins, ACS, or IDCRL has a completed migration behind it.


Sources