ACS Blog

 

M365 Price Hike + Windows 11 Secure Boot Deadline: What Small Businesses Must Do Now

Apr 7, 2026 | Nerds News

Microsoft just dropped a stack of changes that every small business owner needs to know about — and a few of them are going to land on your IT budget within the next 90 days. Here’s the full breakdown from today’s Nerds News: what’s happening, why it matters, and exactly what to do about it.

Microsoft 365 Pricing: The 5–33% Hike Hitting July 1

Microsoft just confirmed another round of pricing changes — and this one is going to land squarely on small business IT budgets. Effective July 1, 2026, Microsoft 365 plans, Copilot add-ons, Defender, and several IT management products are seeing increases of 5% to 33% depending on the SKU.

If you’re running your business on M365 — and most of you are — this matters. A 10% jump on a 25-seat tenant can mean hundreds of dollars a month in unplanned spend, and the higher-tier security and Copilot add-ons are taking the steepest hits. Nobody likes opening a renewal invoice 30% bigger than last year’s.

Here’s the good news: there’s a known workaround that buys you another 12 months at today’s pricing. If you’re on a monthly commitment, switching to an annual commitment license and renewing before July 1 locks in current rates for another full year. We’re auditing every client tenant this week and emailing the folks who are affected with a clear action plan — but if you can’t wait for the email, give us a call and we’ll prioritize your renewal.

Windows 11 Secure Boot Certificate Expiring: The April Patch You Can’t Skip

This is one of those situations where Microsoft updates something to break something on purpose, then gives you a couple of months to plan for it. The Windows 11 secure boot certificates are scheduled to expire on June 26, 2026, and devices that don’t pick up Microsoft’s replacement certificate may simply fail to boot after that date.

The replacement is rolling out as part of the April 2026 patch cycle, so the fix is already on its way to your machines. We patch every managed endpoint as aggressively as we can — but here’s the catch: if your computer is powered off during the maintenance window, it never sees the patch. We see this with clients all the time, and the result is always the same: the machine that wasn’t on for the update is the one that breaks first.

The ask is simple: save your work and leave your computers on at night. Auto-save covers most of the risk on the data side, and giving your machine a 2 a.m. reboot window means it gets patched, restarts, and is ready to go in the morning. If you wake up June 26 and discover a workstation that won’t boot, this is the patch that could have prevented it.

Safe Links URL Protection Lands in All M365 Business Plans

You’ve probably seen Safe Links without realizing it — that little "checking this link for security" popup that appears for a beat when you click a URL inside Outlook or Teams. Until recently, it was reserved for the higher-end enterprise plans. Microsoft is now extending it across every Microsoft 365 Business plan, which is a meaningful win for small business security.

Why is Microsoft pushing enterprise-grade security features further down the stack? The honest answer: the volume of email-based attacks targeting small businesses has exploded, and Microsoft is under pressure to protect every tenant, not just the ones paying for E5. We expect to see more of this — features that used to be premium quietly becoming standard.

One important note: Safe Links is not on by default. Turning it on requires a quick policy change in the Microsoft 365 admin center. If you’re an ACS managed services client, this is the kind of thing we just take care of for you — it’ll get layered alongside the Inky and Graphus protections we already deploy. If you’re not on a managed plan, ask your IT person (or an AI assistant) to walk you through enabling Safe Links policies for your tenant.

AI-Generated Phishing Is Now Aimed Squarely at Small Businesses

For years, the playbook for spotting a phishing email was simple: look for the typos, the awkward grammar, the "Dear valued customer" opener that no real company would ever use. That playbook is officially dead. A new report from Acrisure confirms what we’ve been warning clients about for months: attackers are using AI to generate hyper-convincing phishing emails targeted directly at small business employees.

The writing is now better than the average human’s. In a lot of cases, it’s better than almost anyone you’d find in a typical office. The lures are personalized using publicly available data scraped from LinkedIn, your company website, and previous breaches. The result is an email that looks like it came from a vendor you actually use, asking you to do something that sounds completely reasonable — until you click the link and hand over your password.

Here’s the rule we want every employee to internalize: never enter a username and password into anything you reached from an email link unless you are absolutely positive it’s legitimate. Type the URL yourself, or use a saved bookmark. And if you don’t already have a security awareness training program in place — including phishing simulations — that’s the single highest-ROI security investment you can make right now. We can help you set one up.

Google Forms Adds Gemini AI Question Generator

Quick hit on the Google side: Google Forms can now auto-generate survey questions using Gemini AI. You describe what you’re trying to learn from your respondents and Forms drafts the question set for you.

Honest take after testing it: the AI features bolted onto legacy productivity tools haven’t really impressed us yet. The output is fine, but we’ve consistently gotten better results by just asking a dedicated AI assistant (Claude, ChatGPT, or similar) to draft a survey for a specific purpose, then pasting the questions into Forms manually. It’s not bad — it’s just not the revolution Google is marketing it as.

Still, if you’re already living in Google Workspace and want a faster way to spin up a basic feedback form, this is a nice quality-of-life improvement.

Cross-Signed Kernel Drivers Deprecated: Check Your Old Hardware

This one is going to sneak up on a few businesses. The April Windows 11 update deprecates cross-signed kernel drivers — a category of older drivers that didn’t go through Microsoft’s modern driver-signing process. After the patch lands, those drivers will no longer be considered legitimate, and any hardware that depends on them will stop working.

For most clients running modern PCs and standard peripherals, this is a non-event. Where it bites is the long tail of specialty equipment: older scanners, point-of-sale terminals, label printers, scientific instruments, industrial control devices, and one-off custom hardware that hasn’t seen a driver update in years. If you run anything in your office that you’d describe as "old but it works," this is the time to check whether the manufacturer ever issued a modern signed driver.

If you’re an ACS managed client, we’re already auditing for this in our patch compatibility checks. If you’re not — and you have an oddball piece of hardware you can’t afford to lose — call us before April patches roll out and we’ll help you verify it.

Key Takeaways for This Week

  • Renew M365 annual licenses before July 1 if you want to lock in current pricing for another year.
  • Leave your computers on overnight so the April Windows 11 patch (with the secure boot certificate fix) can install before June 26.
  • Turn on Safe Links policies in your M365 admin center — it’s now free in every Business plan.
  • Train your team on AI-generated phishing. The old grammar-and-typo tells are gone. The rule: never type your password into anything you reached from an email link.
  • Audit any old or specialty hardware before April patches deploy — cross-signed kernel drivers are being deprecated.

Don’t Want to Track All This Yourself?

Every one of the items above is something an ACS managed services client doesn’t have to think about. We audit, we patch, we email you when it matters, and we handle the rest. If you’re tired of finding out about Microsoft changes the day they break something, we should talk.

Schedule a free IT consultation →

New episodes of Nerds News drop a few times a week. Subscribe on YouTube so you don’t miss the next briefing.