
Quick M365 Updates
Storm-2949 Attack: How a Single Identity Compromise Turned into a Cloud-Wide Breach
The Storm-2949 attack shows how hackers use different approaches until they gain full Microsoft 365 cloud access.
9 min read
Microsoft has officially announced that passkeys will become the default authentication method in Microsoft Entra, replacing Microsoft-provided SMS and voice authentication. The change begins rolling out on September 1, 2026, with the transition completing on February 1, 2027.
Microsoft is adding two new PowerShell settings that let admins control who can join federated group chats in Microsoft Teams. These settings are disabled by default and will roll out globally between late July and late September 2026.
Microsoft has introduced cross-tenant message recall in Exchange Online. This feature allows users to recall emails sent to external Microsoft 365 tenants. It is disabled by default and works only when the receiving organization explicitly enables it and adds the sender’s Microsoft Entra tenant IDs to an allow list via PowerShell. The rollout begins in mid-August 2026, delivering a secure recall experience for cross-organization collaboration.
Microsoft’s Network Data Security helps protect sensitive company data when people use AI tools, cloud apps, or websites outside of managed Microsoft 365 apps. It checks data in real time as it is being uploaded, pasted, or shared, and can block it if it breaks company rules. It works by combining Microsoft Purview’s data protection with Microsoft Entra’s network control to make sure sensitive information doesn’t accidentally leave the organization.
Microsoft recently introduced manual incident creation in preview for Defender to help security teams investigate threats beyond automated detections. Analysts can now instantly track, manage, and correlate user reported threats and other security findings, even when no alert is generated automatically.
Microsoft has introduced two new service plans named ‘Entra Conditional Access for Agents’ and ‘Entra ID Protection for Agents’ under Microsoft 365 Agent and E7 licenses. Starting in July 2026, organizations using agent security capabilities must ensure they have the required Microsoft 365 Agent or E7 licenses to continue accessing these features without disruption. This blog explains the licensing update, its impact on organizations, and the steps admins should take to ensure AI agents remain protected.
Struggling to automate secure monitor manage M365?
Try AdminDroid for Free!Anushya is a Microsoft 365 practitioner with 5 years of experience focused on administrative controls and security configurations. She contributes to technical knowledge resources focused on helping IT teams simplify Microsoft 365 management. Her work centers on practical implementation patterns that help administrators apply security settings step-by-step and strengthen day-to-day administrative control across environments.

The Storm-2949 attack shows how hackers use different approaches until they gain full Microsoft 365 cloud access.
9 min read

Compare Microsoft 365 E5 vs E7's features, pricing, preview limitations, and decision factors to determine if the $99 E7 upgrade is worth it.
10 min read

Beware of Fake O365 login pages. Configure Microsoft 365 Company Branding to reduce credential phishing attacks.
10 min read

Monitoring Azure AD Sign-in logs and enabling risk policies to prevent Password Spray Attacks.
8 min read

Review permissions granted to applications and take remediations to block malicious applications in Office 365
6 min read

Configure and manage user consent to applications in office 365 to avoid consent phishing attacks.
5 min read

Passkeys become the default authentication method in Entra as Microsoft retires SMS and voice. Learn the timeline and migration steps.
6 min read

Learn how Network Data Security combines Microsoft Purview and Entra to prevent sensitive data leaks to AI and SaaS apps.
5 min read

Discover how to manage inactive SharePoint sites automatically using Power Automate in Microsoft 365 for better governance and cleanup.
11 min read

Discover why attackers target workload identities and how to detect, remediate, and secure them in Microsoft Entra ID.
13 min read

Detect Storm-2949 attacks in Microsoft 365 using AdminDroid. Identify and act early before it escalates into a cloud breach
8 min read

Learn how to control unmanaged device access in SharePoint Online to protect data by limiting or blocking access from non-compliant devices at tenant and site level.
11 min read

Build a review workflow to remove or disable inactive guests using Power Automate, improving governance over external access in M365
13 min read

Explore Microsoft’s new Security Dashboard for AI in public preview to monitor AI assets, risks, and security posture in one place.
6 min read

Learn how to control external file sharing in SharePoint with approval workflow using Power Automate in Microsoft 365.
16 min read

Microsoft is integrating Viva Engage communities into Teams. Explore the rollout timeline and what this means for daily collaboration.
4 min read

Microsoft Graph now supports Message Trace to help you track emails easily and programmatically through modern REST-based endpoints.
5 min read

Microsoft’s new Intune security enforcement could block access to outdated M365 apps like Outlook & Teams, if latest versions aren’t updated.
5 min read