
Active Directory Tiered Administration Model
Learn how to implement the Active Directory tiered administration model to reduce credential exposure and prevent lateral movement attacks.
14 min read
Microsoft is retiring One-Time Passcode (SPO OTP) authentication and transitioning to Entra B2B guest accounts for external users. This ensures that SharePoint and OneDrive external collaboration is governed by the same security and compliance standards as internal access. SPO OTP method will be fully retired by August 31, 2026, following rollout beginning in May 2026.
Microsoft now allows admins to enforce a default expiration period for “People in your organization” sharing links in SharePoint Online and OneDrive. By configuring maximum and recommended expiration values, admins can prevent internal links from staying active indefinitely. This update helps reduce stale access while maintaining flexible and secure collaboration.
Starting March 3, 2026, Microsoft is introducing a completely reimagined SharePoint experience in Microsoft 365, designed to make collaboration smarter, faster, and more intuitive. The new experience features a redesigned app bar categorized into three core jobs - Discover, Publish, and Build along with AI-powered tools and a neutral theme.
Microsoft Entra Kerberos provides a simpler way to set up hybrid-joined devices by reducing the need for Microsoft Entra Connect or Active Directory Federation Services. By using cloud-based authentication with Microsoft Entra ID, organizations can streamline device onboarding and simplify hybrid deployments.
Tracking Microsoft 365 licenses can be challenging for many organizations. To simplify this, Microsoft introduced the Cloud Licensing beta API in Microsoft Graph (preview), giving admins and developers granular control. Instead of just showing a flat license count, it supports batch tracking, queuing users when licenses run out, and quickly identifying assignment errors.
Starting in late February 2026, Microsoft Teams Mobile (Android & iOS) will prompt users to choose between Edge and the default browser when opening non-Office and PDF links. While Microsoft presents this as a usability update, the flow clearly promotes Edge within the decision screen. It’s less forceful than before, but still a built-in nudge toward Microsoft’s browser. The feature is enabled by default for all tenants but can be disabled by admins via PowerShell.
Struggling to automate secure monitor manage M365?
Try AdminDroid for Free!Explore hands-on guides, admin tips, and automation to simplify Active Directory management.

Learn how to implement the Active Directory tiered administration model to reduce credential exposure and prevent lateral movement attacks.
14 min read

Learn how to configure and manage password policies in Active Directory to enforce strong passwords and secure your environment.
11 min read

Explore step-by-step methods to identify insecure RC4 usage in Active Directory Kerberos tickets and disable them to strengthen security.
16 min read

Learn how Group Policy Results Wizard helps troubleshoot Active Directory GPO issues by showing all applied and denied policy settings with clear troubleshooting insights.
10 min read

Explore why Microsoft is disabling NTLM by default in Active Directory and Windows environment and learn how to prepare using NTLM auditing.
4 min read

Discover how to find the account lockout source in Active Directory to quickly pinpoint the cause and resolve recurring user lockouts.
12 min read

Explore why Microsoft deprecates RC4 encryption in Kerberos authentication and learn how to prepare for the upcoming AES enforcement.
6 min read

Learn how to set up Account Lockout Policy in Windows Active Directory to prevent password-guessing attacks on user accounts.
10 min read

Understand Group Policy Objects in Active Directory and learn how GPOs work to control user and computer settings across your domain.
15 min read

Learn all methods to exclude a OU from a GPO in Active Directory, including WMI filters, GPO permissions, item-level targeting, and more.
14 min read

Understand FSMO roles in Active Directory, their types, purpose, and how to transfer or seize them to another domain controllers.
18 min read

Discover the top Microsoft 365 admin blogs of 2025, featuring the latest tips and best practices to help you manage your M365 environment.
15 min read