New Security Detection Report in the Teams Admin Center
Microsoft published a new Security Detection Report in the Teams admin center to provide unified visibility into messaging security detections across Microsoft Teams.
Microsoft published a new Security Detection Report in the Teams admin center to provide unified visibility into messaging security detections across Microsoft Teams.
Microsoft Defender Unified RBAC is becoming the default access model in selected tenants. Tenants still using legacy RBAC will be automatically enabled for Unified RBAC, replacing legacy RBAC as the default authorization source. Security admins should verify their tenant status.
Microsoft is rolling out bot detection for Teams Meetings, requiring an additional approval step before external meeting assistant bots can be admitted from the lobby. Administrators can configure a new policy setting to control bot access tenant-wide, including blocking detected bots entirely.
Microsoft Defender now flags devices still relying on the older Secure Boot 2011 certificates, helping organizations to identify which ones need attention before they begin expiring in June 2026.
Microsoft has released the Microsoft 365 E7 and Agent 365 licenses, updated the pricing for Windows 365 Business and Dragon Copilot, and discontinued the Windows 365 Business with Windows Hybrid Benefit product.
Smart App Control in Windows 11 can now be enabled or disabled at any time without reinstalling the operating system. The April 2026 cumulative update removes the restriction that previously required a full Windows reset to re-enable it.
A new External Domain Anomalies report in the Teams admin center should provide an overview of how users in the tenant interact with people outside the organisation and flag sudden spikes or unusual engagement that fall outside normal patterns.
Microsoft is enabling Unified RBAC for new tenants with Defender for Office 365 Plan 2 starting at the end of May 2026.
Defender for Office 365 URL click alerts are expanding to Microsoft Teams. When users click malicious links in Teams messages, alerts now appear in the Defender portal for faster detection and investigation.
The “Revoke Sessions” action in Microsoft Entra has been updated to invalidate all user sessions, regardless of whether MFA is enforced via Conditional Access or per-user policies.
Organizations should update Secure Boot certificates ahead of the June 2026 expiration deadline. In this post, I share my personal experience deploying these certificates via Intune, encountering a licensing error, working around it with a registry key, resolving a BIOS-related failure, and verifying the final result with PowerShell.
Microsoft is expanding Teams message reporting to Defender for Office 365 Plan 1, allowing users to report suspicious and false-positive messages starting February 2026.
Microsoft will enable new messaging safety protections in Teams for tenants using the default configuration starting January 2026.
Microsoft is introducing Baseline Security Mode in the Microsoft 365 admin center, providing a central dashboard with 18 recommended security settings for Office products, SharePoint, Exchange, Teams, and Entra.
Microsoft will enable ZAP in Teams for organizations with Defender for Office 365 Plan 1 starting in January 2026, with an opt-out option available for security admins.
Legacy IDCRL authentication in SharePoint Online will be retired starting February 2026. Admins should review Purview Audit Logs and update any applications still using legacy protocols.
Microsoft will enforce Content Security Policy (CSP) for SharePoint tenants starting in March 2026. Report-only mode runs from April 2025 to February 2026. Admins should review CSP violations now to avoid broken custom scripts and components once enforcement begins.
Entra ID now supports multi-device passkeys, allowing users to store their passkey in password managers like 1Password for seamless, passwordless sign-in.
Admins can now remove users from Teams group chats and 1:1 conversations directly from Microsoft Defender, helping speed up incident response and containment.
Microsoft is rolling out three new security features to Teams chats and channel conversations: Weaponizable File Protection, Malicious URL Protection, and the ability to report messages as not a security concern.