conditional access

  1. Microsoft 365 Baseline Security Mode: Secure by Default Without Breaking Legacy Workflows

    Microsoft 365 Baseline Security Mode is an opt-in security bundle in the Microsoft 365 admin center that centralizes recommended controls across authentication, files, Exchange Online, SharePoint, OneDrive, Teams, and Entra ID for tenant administrators. That sounds like a switch, and Microsoft...
  2. Microsoft 365 Configuration Drift: How MSPs Prevent Silent Security Erosion

    Most Microsoft 365 configuration drift happens when a tenant’s current security settings gradually diverge from the baseline an MSP or IT team originally deployed, often through small operational changes that accumulate over months without centralized review. That is the core warning in an MSSP...
  3. Kali365 Device-Code Phishing: How It Bypasses MFA in Microsoft 365

    The FBI issued a May 21, 2026 public warning that a phishing-as-a-service platform called Kali365 is targeting Microsoft 365 accounts by abusing device-code authentication to capture OAuth tokens and bypass multi-factor authentication. That makes this less a story about one new phishing kit than...
  4. Exchange Online Ends Direct EAS Certificate Auth by 2026—Move to Entra ID

    Microsoft said on May 8, 2026, that Exchange Online will stop supporting direct Exchange ActiveSync certificate-based authentication by the end of 2026, forcing affected mobile mail clients to authenticate certificates through Microsoft Entra ID instead of presenting them straight to Exchange...
  5. Microsoft Entra External MFA (OIDC): Policy Control Kept, Custom Controls Retire 2026

    Microsoft has quietly removed one of the biggest identity-management frictions for enterprise customers: the inability to cleanly use third-party MFA providers inside Microsoft Entra ID without sacrificing policy control. The new external MFA capability is now generally available, and Microsoft...
  6. Entra ID Conditional Access Tightens Enforcement for All Resources (March 2026 – June 2026)

    Microsoft’s upcoming enforcement change for Conditional Access in Entra ID is a clear pivot toward consistency and defense‑in‑depth: policies that target All resources will now be evaluated even when those policies include resource exclusions, and sign‑ins that request only minimal OpenID...
  7. idPowerApp: Visualizing Conditional Access for Faster CA Governance

    Conditional Access in large tenants is often a map of good intentions and accidental complexity, and idPowerApp promises to redraw that map into clear, printable slides so teams can see, reason about, and remediate policy interactions at a glance. Overview Conditional Access (CA) is one of the...
  8. Windows 365 Cloud Apps: Publish Individual Apps Without Full Cloud PCs (Public Preview)

    Microsoft’s Windows 365 just added a major twist to its Cloud PC story: administrators can now publish individual, cloud‑hosted applications — Outlook, Word, OneDrive, Edge, PowerPoint and line‑of‑business apps — without provisioning a full Cloud PC for every user, with the feature opening as a...
  9. Windows 365 Cloud Apps: App-only streaming for frontline workers

    Microsoft’s decision to let organizations stream single Windows applications from the cloud — instead of entire Cloud PC sessions — marks a pragmatic pivot in how enterprises will adopt Windows 365 for day-to-day workforces and frontline roles. The new Windows 365 Cloud Apps feature, now in...
  10. Windows 365 Updates: Connection Center, CRDR, and Disaster Recovery Plus

    Microsoft's latest updates to the Windows 365 family push the Cloud PC experience closer to a full, resilient desktop replacement — but they also raise important questions for IT about licensing, capacity, and user data protection. The company has expanded the Connection Center experience so...
  11. Copilot Chat Now Integrated in Word, Excel, PowerPoint, Outlook, OneNote | Microsoft 365 AI

    Microsoft is weaving its AI assistant deeper into the Office experience by rolling Copilot Chat and agent capabilities directly into core Microsoft 365 apps — Word, Excel, PowerPoint, Outlook, and OneNote — bringing a unified, in-context chat pane and a raft of new tools aimed at turning an AI...
  12. Windows Backup for Organizations: Intune-Controlled OOBE Restore for Mass Migrations

    Microsoft’s enterprise backup story just took a meaningful step: Windows Backup for Organizations — the tenant-scoped backup and restore experience Microsoft built to ease device refreshes and large-scale Windows migrations — is being exposed to Intune administrators and moving into wider...
  13. Why Microsoft Datacenter IPs Show Up in Sign-In Logs and How to Protect

    A growing number of Microsoft account holders report successful sign‑ins from IP addresses inside Microsoft’s own network despite having two‑factor authentication enabled — an uptick of incidents first detailed in a German investigation and corroborated by threads on Reddit and Microsoft’s own...
  14. VoidProxy AiTM Phishing: Real-Time Session Cookies & MFA Bypass Explained

    A new, industrialized phishing service called VoidProxy is being used by multiple criminal groups to intercept Google and Microsoft sign-ins in real time, harvest credentials, MFA responses and — critically — session cookies that let attackers impersonate users without needing passwords or...
  15. Microsoft to Retire Outlook Lite: Migrate to Outlook Mobile in 2025

    Microsoft will begin retiring the lightweight Outlook Lite Android app on October 6, 2025, blocking new installs that day as it directs users toward the full Outlook mobile client and consolidates engineering around a single, feature-rich Android email experience. Background Outlook Lite...
  16. Change Your Microsoft 365 Password Quickly — Personal or Work

    If you use Microsoft 365, updating your password regularly is one of the quickest — and most effective — ways to reduce your exposure to account takeover, phishing, and password-spraying attacks. This guide walks through three fast, practical ways to change a Microsoft 365 password (personal...
  17. Outlook Lite Migration: Blocked Install Oct 6, 2025, Move to Outlook Mobile

    Microsoft is planning to pull the plug on Outlook Lite’s distribution this October, with multiple technology outlets reporting that new installations will be blocked beginning October 6, 2025, and users being nudged to move to the full Outlook mobile experience. Background / Overview Outlook...
  18. October 2025 Outlook Lite Block: Migration to Outlook for Mobile

    Microsoft is reportedly planning to block fresh installations of Outlook Lite starting in October 2025 as it prepares a broader retirement of the app, forcing users who rely on a lightweight, battery-friendly client to either remain on an aging build or move to the full Outlook for Mobile...
  19. Azure Phase 2 MFA Enforcement: Prepare for Write-Operation Sign-Ins

    Microsoft has confirmed that Phase 2 of its mandatory multi‑factor authentication (MFA) enforcement for Azure will begin a tenant‑by‑tenant rollout this autumn, extending MFA requirements from portal sign‑ins down into the Azure Resource Manager (ARM) control plane and affecting command‑line...
  20. Copilot Agent Diagnostic for Teams: Quick Admin Validation

    Microsoft has quietly added a new diagnostic aimed at keeping Copilot agents working reliably inside Microsoft Teams: the Copilot Agent Functionality Diagnostic — a customer-facing validator now accessible through Microsoft’s diagnostic surfaces and designed to surface licensing, permission, and...