Tech Spotlight | Building a Future-Proof Microsoft 365 Security Practice

Part Four of the Cybersecurity Tech Spotlight Series

Date: Wednesday, October 28 at 11 am PT / 2 pm ET

Most channel security practices don't fail on tooling. They fail because they were built bespoke per client, carried in two people's heads, and rebuilt from scratch every time a vendor, a rule or a Microsoft default changed.

2026 made that expensive. CMMC Phase 2 was suspended in July pending a reform review, while Phase 1 self assessments, SPRS scores and DFARS 252.204-7012 stayed fully in force. The HIPAA Security Rule overhaul is still not final, with OMB now targeting around July 2027. Microsoft retired flat Core incentives on Microsoft 365 for indirect resellers on July 1. Passkeys became the Entra default on September 1 and Microsoft provided SMS and voice MFA retires February 1, 2027. Anyone who built their practice around a deadline or a SKU spent the year rebuilding.

This session is about building for the parts that don't move. Which threats and controls will still be true in five years, what operating discipline makes the practice repeatable rather than heroic, where Microsoft native stops and you buy or partner, and how to design the whole thing so a vendor change or a rule change costs you a week rather than a quarter.


Register for the rest of this series!

Register now!

Date: October 28, 2026

Time: 11:00 AM PT

Duration: 1 Hour


Your e-mail address is used to communicate with you about your registration, related products and services, and offers from select vendors. Refer to our Privacy Policy for additional information.